Skip to content

Commit 84786dd

Browse files
authored
Merge branch 'main' into add_mssql_alerts
2 parents 397b5af + 27e5ea3 commit 84786dd

File tree

3,472 files changed

+238223
-57886
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

3,472 files changed

+238223
-57886
lines changed

.buildkite/pipeline.publish.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json
22

33
env:
4-
SETUP_GVM_VERSION: "v0.5.2"
4+
SETUP_GVM_VERSION: "v0.6.0"
55
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
66
DOCKER_COMPOSE_VERSION: "v2.24.1"
77
DOCKER_VERSION: "false"

.buildkite/pipeline.schedule-daily.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
name: integrations-schedule-daily
33

44
env:
5-
SETUP_GVM_VERSION: "v0.5.2"
5+
SETUP_GVM_VERSION: "v0.6.0"
66
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
77

88
# The pipeline is triggered by the scheduler every day
@@ -34,7 +34,7 @@ steps:
3434
env:
3535
SERVERLESS: "false"
3636
FORCE_CHECK_ALL: "true"
37-
STACK_VERSION: 8.19.4-SNAPSHOT
37+
STACK_VERSION: 8.19.8-SNAPSHOT
3838
PUBLISH_COVERAGE_REPORTS: "true"
3939
depends_on:
4040
- step: "check"
@@ -48,7 +48,7 @@ steps:
4848
env:
4949
SERVERLESS: "false"
5050
FORCE_CHECK_ALL: "true"
51-
STACK_VERSION: 8.19.4-SNAPSHOT
51+
STACK_VERSION: 8.19.8-SNAPSHOT
5252
STACK_LOGSDB_ENABLED: "true"
5353
PUBLISH_COVERAGE_REPORTS: "false"
5454
depends_on:
@@ -86,13 +86,13 @@ steps:
8686
if: |
8787
build.env('TEST_PACKAGES_BASIC_SUBSCRIPTION') == "true"
8888
89-
- label: "Check integrations local stacks - Stack Version v9.2"
89+
- label: "Check integrations local stacks - Stack Version v9.3"
9090
trigger: "integrations"
9191
build:
9292
env:
9393
SERVERLESS: "false"
9494
FORCE_CHECK_ALL: "true"
95-
STACK_VERSION: 9.2.0-SNAPSHOT
95+
STACK_VERSION: 9.3.0-SNAPSHOT
9696
PUBLISH_COVERAGE_REPORTS: "false"
9797
depends_on:
9898
- step: "check"

.buildkite/pipeline.schedule-weekly.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
name: integrations-schedule-weekly
33

44
env:
5-
SETUP_GVM_VERSION: "v0.5.2"
5+
SETUP_GVM_VERSION: "v0.6.0"
66
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
77

88
# The pipeline is triggered by the scheduler every week
@@ -21,20 +21,20 @@ steps:
2121
env:
2222
SERVERLESS: "false"
2323
FORCE_CHECK_ALL: "true"
24-
STACK_VERSION: 8.19.4-SNAPSHOT
24+
STACK_VERSION: 8.19.8-SNAPSHOT
2525
PUBLISH_COVERAGE_REPORTS: "false"
2626
ELASTIC_PACKAGE_DISABLE_ELASTIC_AGENT_WOLFI: "true"
2727
depends_on:
2828
- step: "check"
2929
allow_failure: false
3030

31-
- label: "Check integrations local stacks and non-wolfi images for Elastic Agent - Stack Version v9.2"
31+
- label: "Check integrations local stacks and non-wolfi images for Elastic Agent - Stack Version v9.3"
3232
trigger: "integrations"
3333
build:
3434
env:
3535
SERVERLESS: "false"
3636
FORCE_CHECK_ALL: "true"
37-
STACK_VERSION: 9.2.0-SNAPSHOT
37+
STACK_VERSION: 9.3.0-SNAPSHOT
3838
PUBLISH_COVERAGE_REPORTS: "false"
3939
ELASTIC_PACKAGE_DISABLE_ELASTIC_AGENT_WOLFI: "true"
4040
depends_on:

.buildkite/pipeline.serverless.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json
22

33
env:
4-
SETUP_GVM_VERSION: "v0.5.2"
4+
SETUP_GVM_VERSION: "v0.6.0"
55
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
66
DOCKER_COMPOSE_VERSION: "v2.24.1"
77
DOCKER_VERSION: "false" # not required to set since system tests are not running yet
@@ -109,6 +109,8 @@ steps:
109109
- label: ":github: Report failed tests"
110110
key: report-failed-tests
111111
command: ".buildkite/scripts/report_issues.sh"
112+
env:
113+
CI_MAX_TESTS_REPORTED: 30
112114
agents:
113115
image: "${LINUX_AGENT_IMAGE}"
114116
cpu: "8"

.buildkite/pipeline.yml

Lines changed: 1 addition & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json
22
env:
3-
SETUP_GVM_VERSION: "v0.5.2"
3+
SETUP_GVM_VERSION: "v0.6.0"
44
DOCKER_COMPOSE_VERSION: "v2.24.1"
55
DOCKER_VERSION: "26.1.2"
66
KIND_VERSION: 'v0.27.0'
@@ -103,21 +103,6 @@ steps:
103103
build.env('BUILDKITE_PULL_REQUEST') != "false" &&
104104
build.env('BUILDKITE_PIPELINE_SLUG') == "integrations"
105105
106-
- label: ":sonarqube: Continuous Code Inspection"
107-
soft_fail: true # FIXME: Coverage is failing, remove this after solving the issue
108-
timeout_in_minutes: 120
109-
env:
110-
VAULT_SONAR_TOKEN_PATH: "kv/ci-shared/platform-ingest/elastic/integrations/sonar-analyze-token"
111-
agents:
112-
image: "docker.elastic.co/cloud-ci/sonarqube/buildkite-scanner:latest"
113-
cpu: "8"
114-
memory: "4G"
115-
command: ".buildkite/scripts/run_sonar_scanner.sh"
116-
artifact_paths:
117-
- build/test-coverage/coverage_merged.xml
118-
if: |
119-
build.env('BUILDKITE_PIPELINE_SLUG') == "integrations"
120-
121106
- label: ":junit: Junit annotate"
122107
agents:
123108
# requires at least "bash", "curl" and "git"

.buildkite/scripts/run_sonar_scanner.sh

Lines changed: 0 additions & 42 deletions
This file was deleted.

.github/CODEOWNERS

Lines changed: 14 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,9 @@
1313
/packages/abnormal_security @elastic/security-service-integrations
1414
/packages/activemq @elastic/obs-infraobs-integrations
1515
/packages/admin_by_request_epm @elastic/security-service-integrations
16+
/packages/agentless_hello_world @elastic/agentless-team
1617
/packages/airflow @elastic/obs-infraobs-integrations
18+
/packages/airlock_digital @elastic/security-service-integrations
1719
/packages/akamai @elastic/security-service-integrations
1820
/packages/amazon_security_lake @elastic/security-service-integrations
1921
/packages/apache @elastic/obs-infraobs-integrations
@@ -84,8 +86,11 @@
8486
/packages/aws_bedrock/data_stream/invocation @elastic/security-service-integrations
8587
/packages/aws_bedrock/data_stream/runtime @elastic/obs-infraobs-integrations
8688
/packages/aws_billing @elastic/obs-infraobs-integrations
89+
/packages/aws_cloudtrail_otel @elastic/obs-infraobs-integrations
8790
/packages/aws_logs @elastic/obs-ds-hosted-services
8891
/packages/aws_mq @elastic/obs-infraobs-integrations
92+
/packages/aws_bedrock_agentcore @elastic/obs-infraobs-integrations
93+
/packages/aws_vpcflow_otel @elastic/obs-infraobs-integrations
8994
/packages/awsfargate @elastic/obs-infraobs-integrations
9095
/packages/awsfirehose @elastic/obs-ds-hosted-services
9196
/packages/azure @elastic/obs-infraobs-integrations @elastic/obs-ds-hosted-services @elastic/security-service-integrations
@@ -173,9 +178,9 @@
173178
/packages/citrix_waf @elastic/integration-experience
174179
/packages/claroty_ctd @elastic/security-service-integrations
175180
/packages/claroty_xdome @elastic/security-service-integrations
176-
/packages/cloud_asset_inventory @elastic/cloud-security-posture
181+
/packages/cloud_asset_inventory @elastic/contextual-security
177182
/packages/cloud_defend @elastic/sec-linux-platform
178-
/packages/cloud_security_posture @elastic/cloud-security-posture
183+
/packages/cloud_security_posture @elastic/contextual-security
179184
/packages/cloudflare @elastic/security-service-integrations
180185
/packages/cloudflare_logpush @elastic/security-service-integrations
181186
/packages/cockroachdb @elastic/obs-infraobs-integrations
@@ -190,6 +195,7 @@
190195
/packages/cyberark_pta @elastic/security-service-integrations
191196
/packages/cyberarkpas @elastic/security-service-integrations
192197
/packages/cybereason @elastic/security-service-integrations
198+
/packages/cyera @elastic/security-service-integrations
193199
/packages/cylance @elastic/security-service-integrations
194200
/packages/darktrace @elastic/security-service-integrations
195201
/packages/ded @elastic/ml-ui @elastic/sec-applied-ml
@@ -202,6 +208,7 @@
202208
/packages/elastic_package_registry @elastic/ecosystem
203209
/packages/elastic_security @elastic/security-service-integrations
204210
/packages/elasticsearch @elastic/stack-monitoring
211+
/packages/aws_elb_otel @elastic/obs-infraobs-integrations
205212
/packages/endace @elastic/integration-experience @elastic/sec-linux-platform
206213
/packages/endace/data_stream/flow @elastic/sec-linux-platform
207214
/packages/endace/data_stream/log @elastic/integration-experience
@@ -212,7 +219,7 @@
212219
/packages/entro @elastic/security-service-integrations
213220
/packages/envoyproxy @elastic/obs-infraobs-integrations
214221
/packages/eset_protect @elastic/security-service-integrations
215-
/packages/ess_billing @elastic/customer-architects
222+
/packages/ess_billing @elastic/customer-architects @elastic/obs-infraobs-integrations
216223
/packages/etcd @elastic/obs-infraobs-integrations
217224
/packages/extrahop @elastic/security-service-integrations
218225
/packages/f5_bigip @elastic/security-service-integrations
@@ -269,6 +276,7 @@
269276
/packages/hta @elastic/sec-applied-ml
270277
/packages/http_endpoint @elastic/security-service-integrations
271278
/packages/httpjson @elastic/security-service-integrations
279+
/packages/ibm_qradar @elastic/security-service-integrations
272280
/packages/ibmmq @elastic/obs-infraobs-integrations
273281
/packages/iis @elastic/obs-infraobs-integrations
274282
/packages/iis_otel @elastic/obs-infraobs-integrations
@@ -293,6 +301,7 @@
293301
/packages/juniper_srx @elastic/integration-experience
294302
/packages/kafka @elastic/obs-infraobs-integrations
295303
/packages/kafka_log @elastic/obs-infraobs-integrations
304+
/packages/keeper_security_siem_integration @elastic/security-service-integrations
296305
/packages/keycloak @elastic/security-service-integrations
297306
/packages/kibana @elastic/stack-monitoring
298307
/packages/kubernetes @elastic/obs-ds-hosted-services
@@ -327,6 +336,7 @@
327336
/packages/mysql_otel @elastic/obs-infraobs-integrations
328337
/packages/nagios_xi @elastic/obs-infraobs-integrations
329338
/packages/nats @elastic/obs-infraobs-integrations
339+
/packages/neon_cyber @elastic/security-service-integrations
330340
/packages/netflow @elastic/integration-experience
331341
/packages/netscout @elastic/integration-experience
332342
/packages/netskope @elastic/security-service-integrations
@@ -425,6 +435,7 @@
425435
/packages/system/data_stream/load @elastic/obs-infraobs-integrations
426436
/packages/system/data_stream/memory @elastic/obs-infraobs-integrations
427437
/packages/system/data_stream/network @elastic/obs-infraobs-integrations
438+
/packages/system/data_stream/ntp @elastic/obs-infraobs-integrations
428439
/packages/system/data_stream/process @elastic/obs-infraobs-integrations
429440
/packages/system/data_stream/process_summary @elastic/obs-infraobs-integrations
430441
/packages/system/data_stream/security @elastic/sec-windows-platform

.github/ISSUE_TEMPLATE/integration_bug.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,12 @@ body:
1919
- Active Directory Entity Analytics [entityanalytics_ad]
2020
- ActiveMQ [activemq]
2121
- Admin By Request EPM [admin_by_request_epm]
22+
- Agentless Hello World [agentless_hello_world]
2223
- Airflow [airflow]
24+
- Airlock Digital [airlock_digital]
2325
- Akamai [akamai]
2426
- AlienVault OTX [ti_otx]
27+
- Amazon Bedrock AgentCore [aws_bedrock_agentcore]
2528
- Amazon Bedrock [aws_bedrock]
2629
- Amazon Data Firehose [awsfirehose]
2730
- Amazon MQ [aws_mq]
@@ -41,8 +44,11 @@ body:
4144
- Auditd Manager [auditd_manager]
4245
- Auth0 [auth0]
4346
- authentik [authentik]
47+
- AWS CloudTrail Logs OpenTelemetry Assets [aws_cloudtrail_otel]
4448
- AWS Cost and Usage Report (CUR 2.0) [aws_billing]
49+
- AWS ELB OpenTelemetry Assets [aws_elb_otel]
4550
- AWS Fargate (for ECS clusters) [awsfargate]
51+
- AWS VPC Flow Logs OpenTelemetry Assets [aws_vpcflow_otel]
4652
- AWS [aws]
4753
- Azure AI Foundry [azure_ai_foundry]
4854
- Azure App Service [azure_app_service]
@@ -132,6 +138,7 @@ body:
132138
- Cyberark Privileged Threat Analytics [cyberark_pta]
133139
- Cybereason [cybereason]
134140
- Cybersixgill [ti_cybersixgill]
141+
- Cyera [cyera]
135142
- CylanceProtect Logs (Deprecated) [cylance]
136143
- Cyware Intel Exchange [ti_cyware_intel_exchange]
137144
- Darktrace [darktrace]
@@ -194,6 +201,7 @@ body:
194201
- Host Traffic Anomalies [hta]
195202
- HPE Aruba CX [hpe_aruba_cx]
196203
- IBM MQ [ibmmq]
204+
- IBM QRadar [ibm_qradar]
197205
- IIS OpenTelemetry assets [iis_otel]
198206
- IIS [iis]
199207
- Imperva Cloud WAF [imperva_cloud_waf]
@@ -214,6 +222,7 @@ body:
214222
- Juniper NetScreen (Deprecated) [juniper_netscreen]
215223
- Juniper SRX [juniper_srx]
216224
- Kafka [kafka]
225+
- Keeper Security [keeper_security_siem_integration]
217226
- Keycloak [keycloak]
218227
- Kibana [kibana]
219228
- Kubernetes OpenTelemetry Assets [kubernetes_otel]
@@ -253,6 +262,7 @@ body:
253262
- MySQL [mysql]
254263
- Nagios XI [nagios_xi]
255264
- NATS [nats]
265+
- Neon Cyber [neon_cyber]
256266
- NetFlow Records [netflow]
257267
- Netskope [netskope]
258268
- Network Beaconing Identification [beaconing]

.github/ISSUE_TEMPLATE/integration_feature_request.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,12 @@ body:
1919
- Active Directory Entity Analytics [entityanalytics_ad]
2020
- ActiveMQ [activemq]
2121
- Admin By Request EPM [admin_by_request_epm]
22+
- Agentless Hello World [agentless_hello_world]
2223
- Airflow [airflow]
24+
- Airlock Digital [airlock_digital]
2325
- Akamai [akamai]
2426
- AlienVault OTX [ti_otx]
27+
- Amazon Bedrock AgentCore [aws_bedrock_agentcore]
2528
- Amazon Bedrock [aws_bedrock]
2629
- Amazon Data Firehose [awsfirehose]
2730
- Amazon MQ [aws_mq]
@@ -41,8 +44,11 @@ body:
4144
- Auditd Manager [auditd_manager]
4245
- Auth0 [auth0]
4346
- authentik [authentik]
47+
- AWS CloudTrail Logs OpenTelemetry Assets [aws_cloudtrail_otel]
4448
- AWS Cost and Usage Report (CUR 2.0) [aws_billing]
49+
- AWS ELB OpenTelemetry Assets [aws_elb_otel]
4550
- AWS Fargate (for ECS clusters) [awsfargate]
51+
- AWS VPC Flow Logs OpenTelemetry Assets [aws_vpcflow_otel]
4652
- AWS [aws]
4753
- Azure AI Foundry [azure_ai_foundry]
4854
- Azure App Service [azure_app_service]
@@ -132,6 +138,7 @@ body:
132138
- Cyberark Privileged Threat Analytics [cyberark_pta]
133139
- Cybereason [cybereason]
134140
- Cybersixgill [ti_cybersixgill]
141+
- Cyera [cyera]
135142
- CylanceProtect Logs (Deprecated) [cylance]
136143
- Cyware Intel Exchange [ti_cyware_intel_exchange]
137144
- Darktrace [darktrace]
@@ -194,6 +201,7 @@ body:
194201
- Host Traffic Anomalies [hta]
195202
- HPE Aruba CX [hpe_aruba_cx]
196203
- IBM MQ [ibmmq]
204+
- IBM QRadar [ibm_qradar]
197205
- IIS OpenTelemetry assets [iis_otel]
198206
- IIS [iis]
199207
- Imperva Cloud WAF [imperva_cloud_waf]
@@ -214,6 +222,7 @@ body:
214222
- Juniper NetScreen (Deprecated) [juniper_netscreen]
215223
- Juniper SRX [juniper_srx]
216224
- Kafka [kafka]
225+
- Keeper Security [keeper_security_siem_integration]
217226
- Keycloak [keycloak]
218227
- Kibana [kibana]
219228
- Kubernetes OpenTelemetry Assets [kubernetes_otel]
@@ -253,6 +262,7 @@ body:
253262
- MySQL [mysql]
254263
- Nagios XI [nagios_xi]
255264
- NATS [nats]
265+
- Neon Cyber [neon_cyber]
256266
- NetFlow Records [netflow]
257267
- Netskope [netskope]
258268
- Network Beaconing Identification [beaconing]

.github/workflows/bump-elastic-stack-version.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
- uses: actions/checkout@v5
2626

2727
- name: Install Updatecli in the runner
28-
uses: updatecli/updatecli-action@0224b21c3687ac1a7510298d58c9a42db84e5814 #v2.92.0
28+
uses: updatecli/updatecli-action@5ca36367fadc6ad94d590984fd9c696e783ec635 #v2.96.0
2929

3030
- name: Select diff action
3131
if: ${{ github.event_name == 'pull_request' }}

0 commit comments

Comments
 (0)