additional integration support - cisco secure email gateway - rapid7 threat command

Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
This commit is contained in:
reyesj2
2024-11-15 11:39:01 -06:00
parent ec5a6aec41
commit 44ec237447
6 changed files with 322 additions and 0 deletions
+176
View File
@@ -3211,6 +3211,50 @@ elasticsearch:
set_priority:
priority: 50
min_age: 30d
so-logs-cisco_secure_email_gateway_x_log:
index_sorting: false
index_template:
composed_of:
- logs-cisco_secure_email_gateway.log@package
- logs-cisco_secure_email_gateway.log@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-cisco_secure_email_gateway.log@custom
index_patterns:
- logs-cisco_secure_email_gateway.log-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-cisco_umbrella_x_log:
index_sorting: false
index_template:
@@ -10399,6 +10443,138 @@ elasticsearch:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_rapid7_threat_command_x_alert:
index_sorting: false
index_template:
composed_of:
- logs-ti_rapid7_threat_command.alert@package
- logs-ti_rapid7_threat_command.alert@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-ti_rapid7_threat_command.alert@custom
index_patterns:
- logs-ti_rapid7_threat_command.alert-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_rapid7_threat_command_x_ioc:
index_sorting: false
index_template:
composed_of:
- logs-ti_rapid7_threat_command.ioc@package
- logs-ti_rapid7_threat_command.ioc@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-ti_rapid7_threat_command.ioc@custom
index_patterns:
- logs-ti_rapid7_threat_command.ioc-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_rapid7_threat_command_x_vulnerability:
index_sorting: false
index_template:
composed_of:
- logs-ti_rapid7_threat_command.vulnerability@package
- logs-ti_rapid7_threat_command.vulnerability@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-ti_rapid7_threat_command.vulnerability@custom
index_patterns:
- logs-ti_rapid7_threat_command.vulnerability-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_recordedfuture_x_latest_ioc-template:
index_sorting: false
index_template:
@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}
@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}
@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}
@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}