-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SIEMINT-69] DDS: Cisco Secure Endpoint: Crawler Integration v1.0.0 #17958
[SIEMINT-69] DDS: Cisco Secure Endpoint: Crawler Integration v1.0.0 #17958
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, some copy suggestions.
@@ -0,0 +1,1949 @@ | |||
{ | |||
"title": "Cisco Secure Endpoint - Event", | |||
"description": " This dashboard provides detailed insights into the event logs generated by Cisco Secure Endpoint.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"description": " This dashboard provides detailed insights into the event logs generated by Cisco Secure Endpoint.", | |
"description": "This dashboard provides detailed insights into the event logs generated by Cisco Secure Endpoint.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the comment. Have made the changes.
cisco_secure_endpoint/README.md
Outdated
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC(Virtual Private Cloud), directly provide the API Host URL. | | ||
| Client ID | Client ID from Cisco Secure Endpoint. | | ||
| API Key | API Key from Cisco Secure Endpoint. | | ||
| Get Endpoint Details | Keep it "true" to collect endpoint metadata for Cisco Secure Endpoint Event Logs, otherwise "false". | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Get Endpoint Details | Keep it "true" to collect endpoint metadata for Cisco Secure Endpoint Event Logs, otherwise "false". | | |
| Get Endpoint Details | Keep it "true" to collect endpoint metadata for Cisco Secure Endpoint Event Logs, otherwise "false". | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the comment. Have made the changes.
cisco_secure_endpoint/README.md
Outdated
|
||
| Cisco Secure Endpoint Parameters | Description | | ||
| -------------------- | ------------ | | ||
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC(Virtual Private Cloud), directly provide the API Host URL. | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC(Virtual Private Cloud), directly provide the API Host URL. | | |
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC (Virtual Private Cloud), directly provide the API Host URL. | |
cisco_secure_endpoint/README.md
Outdated
@@ -0,0 +1,65 @@ | |||
## Overview | |||
|
|||
[Cisco Secure Endpoint][1] is a single-agent solution that provides comprehensive protection, detection, response, and user access coverage to defend against threats to your endpoints. Using cutting-edge technology, it detects and neutralizes malicious activity in real-time, ensuring robust protection for your digital assets. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[Cisco Secure Endpoint][1] is a single-agent solution that provides comprehensive protection, detection, response, and user access coverage to defend against threats to your endpoints. Using cutting-edge technology, it detects and neutralizes malicious activity in real-time, ensuring robust protection for your digital assets. | |
[Cisco Secure Endpoint][1] is a single-agent solution that provides comprehensive protection, detection, response, and user access coverage to defend against threats to your endpoints. Cisco Secure Endpoint can detect and neutralize malicious activity in real time, ensuring robust protection of your digital assets. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the comment. Have made the changes.
cisco_secure_endpoint/README.md
Outdated
[Cisco Secure Endpoint][1] is a single-agent solution that provides comprehensive protection, detection, response, and user access coverage to defend against threats to your endpoints. Using cutting-edge technology, it detects and neutralizes malicious activity in real-time, ensuring robust protection for your digital assets. | ||
|
||
This integration ingests the following logs: | ||
- Audit: Audit logs provide activities performed by user in Cisco Secure Endpoint console. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- Audit: Audit logs provide activities performed by user in Cisco Secure Endpoint console. | |
- Audit: Audit logs provide activities performed by a user in the Cisco Secure Endpoint console. |
cisco_secure_endpoint/README.md
Outdated
--> Refer the below Steps to create Client ID and API Key: | ||
1. Log in to your Cisco Secure Endpoint Console. Click on the Left side Menu Panel. | ||
2. Select `Administration`, Inside that select `Organization Settings`. | ||
3. Click `Configure API Credentials` under `Features` section, to generate the new API Credentials. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
3. Click `Configure API Credentials` under `Features` section, to generate the new API Credentials. | |
3. Click `Configure API Credentials` under the `Features` section to generate new API credentials. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the comment. Have made the changes.
cisco_secure_endpoint/README.md
Outdated
1. Log in to your Cisco Secure Endpoint Console. Click on the Left side Menu Panel. | ||
2. Select `Administration`, Inside that select `Organization Settings`. | ||
3. Click `Configure API Credentials` under `Features` section, to generate the new API Credentials. | ||
4. Click on the `New API Credentials` button located at the right side under section `Legacy API Credentials (version 0 and 1)`. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
4. Click on the `New API Credentials` button located at the right side under section `Legacy API Credentials (version 0 and 1)`. | |
4. Click on the `New API Credentials` button located at the right side under the `Legacy API Credentials (version 0 and 1)` section. |
cisco_secure_endpoint/README.md
Outdated
2. Select `Administration`, Inside that select `Organization Settings`. | ||
3. Click `Configure API Credentials` under `Features` section, to generate the new API Credentials. | ||
4. Click on the `New API Credentials` button located at the right side under section `Legacy API Credentials (version 0 and 1)`. | ||
5. Add the below details in the pop-up: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
5. Add the below details in the pop-up: | |
5. Add the following information in the pop-up modal: |
cisco_secure_endpoint/README.md
Outdated
- Application Name: Any preferable name | ||
- Scope: Select `Read-only` | ||
- Click on `Create`. | ||
- Once you click on create, the redirected page will display the client ID(i.e: 3rd Party API client ID) and API Key values. | ||
- NOTE: Please make a note of the API Key, as it will only be displayed once. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- Application Name: Any preferable name | |
- Scope: Select `Read-only` | |
- Click on `Create`. | |
- Once you click on create, the redirected page will display the client ID(i.e: 3rd Party API client ID) and API Key values. | |
- NOTE: Please make a note of the API Key, as it will only be displayed once. | |
- Application Name: Any preferable name. | |
- Scope: Select `Read-only`. | |
- Click `Create`. | |
- Once you click **Create**, the redirected page will display the client ID (like a third party API client ID) and API Key values. | |
- **Note:** Make a note of the API Key, as it will only be displayed once. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the comment. Have made the changes.
cisco_secure_endpoint/README.md
Outdated
|
||
### Logs | ||
|
||
The Cisco Secure Endpoint integration collects and forwards Cisco Secure Endpoint Audit and Event logs to Datadog. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The Cisco Secure Endpoint integration collects and forwards Cisco Secure Endpoint Audit and Event logs to Datadog. | |
The Cisco Secure Endpoint integration collects and forwards Cisco Secure Endpoint audit and event logs to Datadog. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, two small suggestions.
cisco_secure_endpoint/README.md
Outdated
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC (Virtual Private Cloud), directly provide the API Host URL. | | ||
| Client ID | Client ID from Cisco Secure Endpoint. | | ||
| API Key | API Key from Cisco Secure Endpoint. | | ||
| Get Endpoint Details | Keep it "true" to collect endpoint metadata for Cisco Secure Endpoint Event Logs, otherwise "false". | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Get Endpoint Details | Keep it "true" to collect endpoint metadata for Cisco Secure Endpoint Event Logs, otherwise "false". | | |
| Get Endpoint Details | Keep it "true" to collect endpoint metadata for Cisco Secure Endpoint event logs, otherwise "false". | |
cisco_secure_endpoint/README.md
Outdated
|
||
| Cisco Secure Endpoint Parameters | Description | | ||
| -------------------- | ------------ | | ||
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC (Virtual Private Cloud), directly provide the API Host URL. | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| API Host URL |The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC (Virtual Private Cloud), directly provide the API Host URL. | | |
| API Host URL | The API Host URL for Cisco Secure Endpoint Cloud is "https://api.\<region\>.apm.cisco.com". Adjust the "region" part based on the region of the Cisco Secure Endpoint server. If Cisco Secure Endpoint is hosted on VPC (Virtual Private Cloud), directly provide the API Host URL. | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Have made the changes.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approved
46f6ee1
I rechecked the log file and it looks good for me, I have reapproved the PR 👍 |
…17958) * Cisco Secure Endpoint: Crawler Integration v1.0.0 * Made changes for validation checks failure * Changed images folder path * Updated dashboard * Renamed log files * Resolved validate log errors * Updated README and manifest * Updated as per PR review comments * Added changes as per PR comments * Updated title as per Cisco Secure Endpoint without Assets PR * Updated as per PR review * Updated test.yaml * made changes for event type in test.yaml * Added changes in test pipeline * Updated test pipeline file * Update: display_on_public_website from False to True * Update: Review comments for dashboards * Update: change dashboard images as per updated dashboards. * Update: dashboard and pipeline * Update: Add pipeline results * updated menifest.json file. * One More * Added disclaimer and changed title --------- Co-authored-by: manan-crest <[email protected]> Co-authored-by: madhavpandya-crest <[email protected]> Co-authored-by: Austin Lai <[email protected]> aa565a1
What does this PR do?
This is a initial release PR of Cisco Secure Endpoint integration including all the required assets.
Additional Notes
Review checklist (to be filled by reviewers)