Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[windows] Add Windows AppLocker Data Stream (MSI and Script)#7279

Merged
efd6 merged 19 commits intoelastic:mainfrom
nicpenning:applocker_msi_and_script
Aug 10, 2023
Merged

[windows] Add Windows AppLocker Data Stream (MSI and Script)#7279
efd6 merged 19 commits intoelastic:mainfrom
nicpenning:applocker_msi_and_script

Conversation

@nicpenning
Copy link
Contributor

@nicpenningnicpenning commentedAug 5, 2023
edited
Loading

  • Enhancement

What does this PR do?

This PR adds the Windows AppLocker MSI and Script data stream which allows the ingestion of those events from the Windows Event Log. This also updates the dashboard with a better title and adds 4 new visualizations to explore the data.

Resolves Part of -#6979

Checklist

  • I have reviewedtips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package'schangelog.yml file.
  • I have verified that Kibana version constraints are current according toguidelines.

image

@elasticmachine
Copy link

elasticmachine commentedAug 5, 2023
edited
Loading

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline ViewTest ViewChangesArtifactspreviewpreview

Expand to view the summary

Build stats

  • Start Time: 2023-08-10T00:52:44.584+0000

  • Duration: 18 min 33 sec

Test stats 🧪

TestResults
Failed0
Passed140
Skipped0
Total140

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@nicpenning
Copy link
ContributorAuthor

/test

1 similar comment
@andrewkroh
Copy link
Member

/test

@elasticmachine
Copy link

elasticmachine commentedAug 9, 2023
edited
Loading

🌐 Coverage report

NameMetrics % (covered/total)Diff
Packages100.0% (6/6)💚
Files90.0% (9/10)👎 -10.0
Classes90.0% (9/10)👎 -10.0
Methods84.545% (93/110)👎 -15.455
Lines92.65% (5458/5891)👍 0.624
Conditionals100.0% (0/0)💚

Copy link
Contributor

@efd6efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Can you provide screen shots showing the dashboard changes.

Also, please make the following change to CODEOWNERS

diff --git a/.github/CODEOWNERS b/.github/CODEOWNERSindex ddcfae883..aacc76f5a 100644--- a/.github/CODEOWNERS+++ b/.github/CODEOWNERS@@ -243,6 +243,7 @@ /packages/websphere_application_server @elastic/obs-infraobs-integrations /packages/windows @elastic/elastic-agent-data-plane @elastic/security-external-integrations /packages/windows/data_stream/applocker_exe_and_dll @elastic/security-external-integrations+/packages/windows/data_stream/applocker_msi_and_script @elastic/security-external-integrations /packages/windows/data_stream/forwarded @elastic/security-external-integrations /packages/windows/data_stream/perfmon @elastic/elastic-agent-data-plane /packages/windows/data_stream/powershell @elastic/security-external-integrations

nicpenning reacted with thumbs up emoji
@efd6
Copy link
Contributor

efd6 commentedAug 9, 2023

/test

@nicpenning
Copy link
ContributorAuthor

Can you provide screen shots showing the dashboard changes.

Also, please make the following change to CODEOWNERS

diff --git a/.github/CODEOWNERS b/.github/CODEOWNERSindex ddcfae883..aacc76f5a 100644--- a/.github/CODEOWNERS+++ b/.github/CODEOWNERS@@ -243,6 +243,7 @@ /packages/websphere_application_server @elastic/obs-infraobs-integrations /packages/windows @elastic/elastic-agent-data-plane @elastic/security-external-integrations /packages/windows/data_stream/applocker_exe_and_dll @elastic/security-external-integrations+/packages/windows/data_stream/applocker_msi_and_script @elastic/security-external-integrations /packages/windows/data_stream/forwarded @elastic/security-external-integrations /packages/windows/data_stream/perfmon @elastic/elastic-agent-data-plane /packages/windows/data_stream/powershell @elastic/security-external-integrations

Do you mean update the .png in the package or add those screenshots to this PR for review?

@nicpenning
Copy link
ContributorAuthor

I added these:
image

And removed the "-" in the title of the dashboard between [Windows Applocker] - Audited Blocked Applications
image

efd6 reacted with thumbs up emoji

@efd6
Copy link
Contributor

/test

Copy link
Contributor

@efd6efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

LGTM

nicpenning reacted with rocket emoji
@efd6efd6 merged commit4c465f2 intoelastic:mainAug 10, 2023
@nicpenningnicpenning deleted the applocker_msi_and_script branchAugust 10, 2023 01:45
@elasticmachine
Copy link

Package windows - 1.30.0 containing this change is available athttps://epr.elastic.co/search?package=windows

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@efd6efd6efd6 approved these changes

@ycombinatorycombinatorAwaiting requested review from ycombinatorycombinator is a code owner automatically assigned from elastic/elastic-agent-data-plane

@leehinmanleehinmanAwaiting requested review from leehinmanleehinman is a code owner automatically assigned from elastic/elastic-agent-data-plane

Assignees

No one assigned

Labels

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

4 participants

@nicpenning@elasticmachine@andrewkroh@efd6

Comments


[8]ページ先頭

©2009-2026 Movatter.jp