additional integration support - cisco secure email gateway - rapid7 threat command

Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
This commit is contained in:
reyesj2
2024-11-15 11:39:01 -06:00
parent ec5a6aec41
commit 44ec237447
6 changed files with 322 additions and 0 deletions

View File

@@ -48,6 +48,7 @@ elasticfleet:
- cisco_ios - cisco_ios
- cisco_ise - cisco_ise
- cisco_meraki - cisco_meraki
- cisco_secure_email_gateway
- cisco_umbrella - cisco_umbrella
- citrix_adc - citrix_adc
- citrix_waf - citrix_waf
@@ -108,6 +109,7 @@ elasticfleet:
- ti_cybersixgill - ti_cybersixgill
- ti_misp - ti_misp
- ti_otx - ti_otx
- ti_rapid7_threat_command
- ti_recordedfuture - ti_recordedfuture
- ti_threatq - ti_threatq
- trendmicro - trendmicro

View File

@@ -3211,6 +3211,50 @@ elasticsearch:
set_priority: set_priority:
priority: 50 priority: 50
min_age: 30d min_age: 30d
so-logs-cisco_secure_email_gateway_x_log:
index_sorting: false
index_template:
composed_of:
- logs-cisco_secure_email_gateway.log@package
- logs-cisco_secure_email_gateway.log@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-cisco_secure_email_gateway.log@custom
index_patterns:
- logs-cisco_secure_email_gateway.log-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-cisco_umbrella_x_log: so-logs-cisco_umbrella_x_log:
index_sorting: false index_sorting: false
index_template: index_template:
@@ -10399,6 +10443,138 @@ elasticsearch:
set_priority: set_priority:
priority: 50 priority: 50
min_age: 30d min_age: 30d
so-logs-ti_rapid7_threat_command_x_alert:
index_sorting: false
index_template:
composed_of:
- logs-ti_rapid7_threat_command.alert@package
- logs-ti_rapid7_threat_command.alert@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-ti_rapid7_threat_command.alert@custom
index_patterns:
- logs-ti_rapid7_threat_command.alert-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_rapid7_threat_command_x_ioc:
index_sorting: false
index_template:
composed_of:
- logs-ti_rapid7_threat_command.ioc@package
- logs-ti_rapid7_threat_command.ioc@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-ti_rapid7_threat_command.ioc@custom
index_patterns:
- logs-ti_rapid7_threat_command.ioc-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_rapid7_threat_command_x_vulnerability:
index_sorting: false
index_template:
composed_of:
- logs-ti_rapid7_threat_command.vulnerability@package
- logs-ti_rapid7_threat_command.vulnerability@custom
- so-fleet_globals-1
- so-fleet_agent_id_verification-1
data_stream:
hidden: false
allow_custom_routing: false
ignore_missing_component_templates:
- logs-ti_rapid7_threat_command.vulnerability@custom
index_patterns:
- logs-ti_rapid7_threat_command.vulnerability-*
priority: 501
template:
settings:
index:
number_of_replicas: 0
policy:
phases:
cold:
actions:
set_priority:
priority: 0
min_age: 60d
delete:
actions:
delete: {}
min_age: 365d
hot:
actions:
rollover:
max_age: 30d
max_primary_shard_size: 50gb
set_priority:
priority: 100
min_age: 0ms
warm:
actions:
set_priority:
priority: 50
min_age: 30d
so-logs-ti_recordedfuture_x_latest_ioc-template: so-logs-ti_recordedfuture_x_latest_ioc-template:
index_sorting: false index_sorting: false
index_template: index_template:

View File

@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}

View File

@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}

View File

@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}

View File

@@ -0,0 +1,36 @@
{
"template": {
"mappings": {
"properties": {
"host": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"related": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"destination": {
"properties":{
"ip": {
"type": "ip"
}
}
},
"source": {
"properties":{
"ip": {
"type": "ip"
}
}
}
}
}
}
}