Skip to content

Commit 294b2d5

Browse files
authored
microsoft_defender_endpoint: add SSL configuration for log data stream (#14885)
1 parent 430377f commit 294b2d5

File tree

4 files changed

+38
-1
lines changed

4 files changed

+38
-1
lines changed

packages/microsoft_defender_endpoint/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "2.43.0"
3+
changes:
4+
- description: Add support for SSL configuration for log data stream.
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/14885
27
- version: "2.42.2"
38
changes:
49
- description: Fix handling of empty string IP values.

packages/microsoft_defender_endpoint/data_stream/log/agent/stream/httpjson.yml.hbs

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ request.method: GET
2121
{{#if proxy_url }}
2222
request.proxy_url: {{proxy_url}}
2323
{{/if}}
24+
{{#if ssl}}
25+
request.ssl: {{ssl}}
26+
{{/if}}
2427
request.transforms:
2528
- set:
2629
target: "header.User-Agent"

packages/microsoft_defender_endpoint/data_stream/log/manifest.yml

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,35 @@ streams:
100100
required: true
101101
show_user: false
102102
default: https://api.securitycenter.windows.com/api/alerts
103+
- name: ssl
104+
type: yaml
105+
title: SSL Configuration
106+
description: SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.
107+
multi: false
108+
required: false
109+
show_user: false
110+
default: |
111+
#certificate_authorities:
112+
# - |
113+
# -----BEGIN CERTIFICATE-----
114+
# MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF
115+
# ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2
116+
# MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB
117+
# BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n
118+
# fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl
119+
# 94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t
120+
# /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP
121+
# PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41
122+
# CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O
123+
# BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux
124+
# 8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D
125+
# 874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw
126+
# 3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA
127+
# H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu
128+
# 8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0
129+
# yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk
130+
# sxSmbIUfc2SGJGCJD4I=
131+
# -----END CERTIFICATE-----
103132
- name: tags
104133
type: text
105134
title: Tags

packages/microsoft_defender_endpoint/manifest.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
format_version: "3.4.0"
22
name: microsoft_defender_endpoint
33
title: Microsoft Defender for Endpoint
4-
version: "2.42.2"
4+
version: "2.43.0"
55
description: Collect logs from Microsoft Defender for Endpoint with Elastic Agent.
66
categories:
77
- "security"

0 commit comments

Comments
 (0)