Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecate Symantec EDR Cloud integration #11915

Open
jamiehynds opened this issue Nov 28, 2024 · 1 comment
Open

Deprecate Symantec EDR Cloud integration #11915

jamiehynds opened this issue Nov 28, 2024 · 1 comment
Labels
Integration:symantec_edr_cloud Symantec EDR Cloud Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations]

Comments

@jamiehynds
Copy link

We currently have two integrations covering the same Symantec platform, causing user confusion and overlap between two integrations.

Symantec EDR Cloud covers Incidents via Symantec's API. Symantec Endpoint Security covers the same incidents, but also events via object storage.

Rather than maintaining two integrations, can we add a deprecation notice to EDR Cloud and advise customers to move to the SES integration. We can then remove the EDR Cloud integration in 9.0.

@jamiehynds jamiehynds added the Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations] label Nov 28, 2024
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@jamiehynds jamiehynds added the Integration:symantec_edr_cloud Symantec EDR Cloud label Nov 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:symantec_edr_cloud Symantec EDR Cloud Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations]
Projects
None yet
Development

No branches or pull requests

2 participants