-
Notifications
You must be signed in to change notification settings - Fork 554
Open
Labels
Integration:admin_by_request_epmAdmin By Request EPMAdmin By Request EPMIntegration:authentikauthentikauthentikIntegration:beyondinsight_password_safeBeyondInsight and Password SafeBeyondInsight and Password SafeIntegration:bitdefenderBitDefender (Community supported)BitDefender (Community supported)Integration:blacklensblacklens.io (Community supported)blacklens.io (Community supported)Integration:carbon_black_cloudVMware Carbon Black CloudVMware Carbon Black CloudIntegration:checkpoint_emailCheck Point Harmony Email & CollaborationCheck Point Harmony Email & CollaborationIntegration:checkpoint_harmony_endpointCheck Point Harmony EndpointCheck Point Harmony EndpointIntegration:cisco_duoCisco DuoCisco DuoIntegration:claroty_ctdClaroty CTDClaroty CTDIntegration:cloudflare_logpushCloudflare LogpushCloudflare LogpushIntegration:crowdstrikeCrowdStrikeCrowdStrikeIntegration:cyberark_epmCyberArk EPMCyberArk EPMIntegration:digital_guardianDigital GuardianDigital GuardianIntegration:entroEntroEntroIntegration:eset_protectESET PROTECTESET PROTECTIntegration:first_epssFirst EPSS (Community supported)First EPSS (Community supported)Integration:google_sccGoogle Security Command CenterGoogle Security Command CenterIntegration:google_workspaceGoogle WorkspaceGoogle WorkspaceIntegration:imperva_cloud_wafImperva Cloud WAFImperva Cloud WAFIntegration:m365_defenderMicrosoft Defender XDRMicrosoft Defender XDRIntegration:microsoft_defender_endpointMicrosoft Defender for EndpointMicrosoft Defender for EndpointIntegration:microsoft_sentinelMicrosoft SentinelMicrosoft SentinelIntegration:mimecastMimecast (Partner supported)Mimecast (Partner supported)Integration:oktaOktaOktaIntegration:qualys_vmdrQualys VMDRQualys VMDRIntegration:sailpoint_identity_scSailpoint Identity Security CloudSailpoint Identity Security CloudIntegration:servicenowServiceNowServiceNowIntegration:spycloudSpyCloud Enterprise Protection (Partner supported)SpyCloud Enterprise Protection (Partner supported)Integration:sublime_securitySublime SecuritySublime SecurityIntegration:symantec_endpoint_securitySymantec Endpoint SecuritySymantec Endpoint SecurityIntegration:sysdigSysdigSysdigIntegration:tenable_ioTenable Vulnerability ManagementTenable Vulnerability ManagementIntegration:ti_crowdstrikeCrowdStrike Falcon IntelligenceCrowdStrike Falcon IntelligenceIntegration:ti_customCustom Threat IntelligenceCustom Threat IntelligenceIntegration:ti_openctiOpenCTIOpenCTIIntegration:withsecure_elementsWithSecure Elements (Community supported)WithSecure Elements (Community supported)Integration:wizWizWizTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Description
Filebeat v8.15.x added the ability to delete request traces on the agent's host[1]. Since #11954 a number of other integrations have come into the version range that can make use of this.
- admin_by_request_epm ssi: add support for request trace deletion #13035
- authentik ssi: add or fix support for request trace deletion #17963
- beyondinsight_password_safe ssi: add support for request trace deletion #13035
- bitdefender ssi: add or fix support for request trace deletion #17963
- blacklens ssi: add support for request trace deletion #13035
- carbon_black_cloud ssi: add support for request trace deletion #13035
- checkpoint_email checkpoint_email,okta,wiz: add support for request trace deletion #11954
- checkpoint_harmony_endpoint ssi: add or fix support for request trace deletion #17963
- cisco_duo ssi: add or fix support for request trace deletion #17963
- claroty_ctd ssi: add or fix support for request trace deletion #17963
- cloudflare_logpush cloudflare_logpush: expand set of supported fields and add data streams #12782
- crowdstrike ssi: add support for request trace deletion #13035
- cyberark_epm [cyberark_epm] Initial release of the CyberArk EPM #12198
- digital_guardian ssi: add or fix support for request trace deletion #17963
- entro ssi: add or fix support for request trace deletion #17963
- eset_protect ssi: add or fix support for request trace deletion #17963
- first_epss ssi: add or fix support for request trace deletion #17963
- google_scc ssi: add support for request trace deletion #13452
- google_secops [google_secops] Initial release of the google secops #12767
- google_workspace ssi: add support for request trace deletion #13035
- imperva_cloud_waf ssi: add support for request trace deletion #13035
- m365_defender ssi: add support for request trace deletion #13452
- microsoft_defender_endpoint ssi: add support for request trace deletion #13452
- microsoft_sentinel ssi: add support for request trace deletion #13452
- mimecast ssi: add support for request trace deletion #13035
- o365 ssi: add support for request trace deletion #13452
- okta checkpoint_email,okta,wiz: add support for request trace deletion #11954 ssi: add support for request trace deletion #13035
- prisma_cloud ssi: add support for request trace deletion #13452
- proofpoint_itm [proofpoint_itm] Initial release of Proofpoint ITM #13153
- qualys_vmdr ssi: add support for request trace deletion #13035
- sailpoint_identity_sc ssi: add support for request trace deletion #13035
- sentinel_one ssi: add support for request trace deletion #13452
- servicenow ssi: add support for request trace deletion #13035
- spycloud ssi: add or fix support for request trace deletion #17963
- sublime_security ssi: add support for request trace deletion #13035
- symantec_endpoint_security ssi: add support for request trace deletion #13035
- sysdig ssi: add or fix support for request trace deletion #17963
- tenable_io ssi: add support for request trace deletion #13452
- tenable_ot_security ssi: add support for request trace deletion #13452
- ti_abusech ssi: add support for request trace deletion #13452
- ti_crowdstrike ssi: add or fix support for request trace deletion #17963
- ti_custom ssi: add or fix support for request trace deletion #17963
- ti_opencti ssi: add or fix support for request trace deletion #17963
- ti_threatq ssi: add support for request trace deletion #13452
- ti_domaintools ssi: add support for request trace deletion #13035
- withsecure_elements ssi: add or fix support for request trace deletion #17963
- wiz checkpoint_email,okta,wiz: add support for request trace deletion #11954
- zscaler_zia ssi: add support for request trace deletion #13452
The list can be obtained by running (there are probably nicer implementations of this, but it works).
yq -o=json 'select(.owner.github == "elastic/security-service-integrations")|select((.conditions.kibana.version|contains("8.18.")) or (.conditions.kibana.version|contains("8.17.")) or (.conditions.kibana.version|contains("8.16.")) or (.conditions.kibana.version|contains("8.15.")))|{"name":.name,"policy":.policy_templates}' packages/**/manifest.yml|jq -c|egrep '"type":"(cel|httpjson|http_endpoint)"'|jq -r .name
A similar list for packages that have not yet come into range (currently at a version before v8.15):
- auth0
- bbot
- carbonblack_edr
- cisa_kevs
- cisco_meraki
- cybereason
- darktrace
- gigamon
- jamf_compliance_reporter
- jumpcloud
- ti_cif3
- ti_cybersixgill
- ti_eclecticiq
- ti_maltiverse
- ti_misp
- ti_threatconnect
- trellix_epo_cloud
- zoom
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Integration:admin_by_request_epmAdmin By Request EPMAdmin By Request EPMIntegration:authentikauthentikauthentikIntegration:beyondinsight_password_safeBeyondInsight and Password SafeBeyondInsight and Password SafeIntegration:bitdefenderBitDefender (Community supported)BitDefender (Community supported)Integration:blacklensblacklens.io (Community supported)blacklens.io (Community supported)Integration:carbon_black_cloudVMware Carbon Black CloudVMware Carbon Black CloudIntegration:checkpoint_emailCheck Point Harmony Email & CollaborationCheck Point Harmony Email & CollaborationIntegration:checkpoint_harmony_endpointCheck Point Harmony EndpointCheck Point Harmony EndpointIntegration:cisco_duoCisco DuoCisco DuoIntegration:claroty_ctdClaroty CTDClaroty CTDIntegration:cloudflare_logpushCloudflare LogpushCloudflare LogpushIntegration:crowdstrikeCrowdStrikeCrowdStrikeIntegration:cyberark_epmCyberArk EPMCyberArk EPMIntegration:digital_guardianDigital GuardianDigital GuardianIntegration:entroEntroEntroIntegration:eset_protectESET PROTECTESET PROTECTIntegration:first_epssFirst EPSS (Community supported)First EPSS (Community supported)Integration:google_sccGoogle Security Command CenterGoogle Security Command CenterIntegration:google_workspaceGoogle WorkspaceGoogle WorkspaceIntegration:imperva_cloud_wafImperva Cloud WAFImperva Cloud WAFIntegration:m365_defenderMicrosoft Defender XDRMicrosoft Defender XDRIntegration:microsoft_defender_endpointMicrosoft Defender for EndpointMicrosoft Defender for EndpointIntegration:microsoft_sentinelMicrosoft SentinelMicrosoft SentinelIntegration:mimecastMimecast (Partner supported)Mimecast (Partner supported)Integration:oktaOktaOktaIntegration:qualys_vmdrQualys VMDRQualys VMDRIntegration:sailpoint_identity_scSailpoint Identity Security CloudSailpoint Identity Security CloudIntegration:servicenowServiceNowServiceNowIntegration:spycloudSpyCloud Enterprise Protection (Partner supported)SpyCloud Enterprise Protection (Partner supported)Integration:sublime_securitySublime SecuritySublime SecurityIntegration:symantec_endpoint_securitySymantec Endpoint SecuritySymantec Endpoint SecurityIntegration:sysdigSysdigSysdigIntegration:tenable_ioTenable Vulnerability ManagementTenable Vulnerability ManagementIntegration:ti_crowdstrikeCrowdStrike Falcon IntelligenceCrowdStrike Falcon IntelligenceIntegration:ti_customCustom Threat IntelligenceCustom Threat IntelligenceIntegration:ti_openctiOpenCTIOpenCTIIntegration:withsecure_elementsWithSecure Elements (Community supported)WithSecure Elements (Community supported)Integration:wizWizWizTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Type
Fields
Give feedbackNo fields configured for Task.