-
Notifications
You must be signed in to change notification settings - Fork 465
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[infoblox_nios] Add Infoblox NIOS package #3129
[infoblox_nios] Add Infoblox NIOS package #3129
Conversation
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
/test |
@jamiehynds Hey again.. :) Fyi I tested the Infoblox rsa module on 7.15 and unfortunately i must say its really bad.... |
Hey @willemdh - we're in the process of rewriting a lot of those RSA modules from scratch, which is exactly what we've done with Infoblox. This integration has been built in collaboration with Infoblox. ECS mappings and dashboards are far superior to the old module. DHCP, DNS and Audit events all supported. Look forward to getting your feedback once it's available. Thanks for the offer of sample logs, but I think we're ok, as we've worked directly with Infoblox. Agent will be a requirement, there will not be a corresponding Filebeat module. |
Thanks for the info @jamiehynds |
@willemdh It should be possible to route data collected by Filebeat into the data stream managed by this integration. It requires some understanding of how the parts work, but I've done this a bit while transitioning between Beats and Agent. In case it helps, here's my unofficial method. https://gist.github.com/andrewkroh/c253717ebe82f2ec47fe003eda99c1dc |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm not finished reviewing, but wanted to leave these comments for now until I get back to it.
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/pipeline_dhcp.yml
Outdated
Show resolved
Hide resolved
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/pipeline_dhcp.yml
Outdated
Show resolved
Hide resolved
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/infoblox_nios/data_stream/log/elasticsearch/ingest_pipeline/pipeline_audit.yml
Show resolved
Hide resolved
🌐 Coverage report
|
What does this PR do?
Checklist
changelog.yml
file.How to test this PR locally
elastic-package test
Screenshots