Skip to content

Add cdr label to all cloud security integrations #9213

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 6 commits into from
Feb 27, 2024

Conversation

CohenIdo
Copy link
Contributor

@CohenIdo CohenIdo commented Feb 21, 2024

Summary

Adding a new subcategory label, cloudsecurity_cdr to all cloud security-related integrations.

solves:

Demo

Screen.Recording.2024-02-21.at.14.33.02.mov

@CohenIdo CohenIdo changed the title add cdr label to all cloud security integrations Add cdr label to all cloud security integrations Feb 21, 2024
@CohenIdo CohenIdo marked this pull request as ready for review February 21, 2024 12:41
@CohenIdo CohenIdo requested review from a team as code owners February 21, 2024 12:41
Copy link
Contributor

@kfirpeled kfirpeled left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, I added minor tweaks

@@ -726,6 +728,8 @@ policy_templates:
description: Collect Amazon GuardDuty logs with Elastic Agent.
data_streams:
- guardduty
categories:
- cloudsecurity_cdr
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you know if security category is missing here? I do see it in the demo but it would mean it will be missing from the Security filter. which I'm not sure it makes sense

@@ -67,6 +67,7 @@ policy_templates:
- containers
- kubernetes
- security
- cloudsecurity_cdr
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: you can add the tag to the root categories section (line 12)

@@ -93,6 +94,7 @@ policy_templates:
multiple: true
categories:
- security
- cloudsecurity_cdr
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: you can add the tag to the root categories section (line 12)
same goes with security - it shouldn't be repeated

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and if you are there, can you please fix the root categories?

categories:
  - aws
  - kubernetes
  - security

it should be only security and cloudsecurity_cdr
aws and kubernetes categories should be only in the relevant supported integrations

@elasticmachine
Copy link

🚀 Benchmarks report

Package google_scc 👍(1) 💚(1) 💔(2)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
asset 1012.15 834.72 -177.43 (-17.53%) 💔
audit 1890.36 1420.45 -469.91 (-24.86%) 💔

Package prisma_cloud 👍(2) 💚(0) 💔(3)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
alert 1579.78 1340.48 -239.3 (-15.15%) 💔
audit 4926.11 3597.12 -1328.99 (-26.98%) 💔
host_profile 1231.53 1031.99 -199.54 (-16.2%) 💔

Package snyk 👍(1) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
vulnerabilities 2724.8 1798.56 -926.24 (-33.99%) 💔

Package wiz 👍(1) 💚(1) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
vulnerability 1964.64 1364.26 -600.38 (-30.56%) 💔

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

History

Copy link

Quality Gate passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No Coverage information No data about Coverage
No Duplication information No data about Duplication

See analysis details on SonarQube

@CohenIdo CohenIdo merged commit 558efe4 into elastic:main Feb 27, 2024
@elasticmachine
Copy link

Package aws - 2.12.1 containing this change is available at https://epr.elastic.co/search?package=aws

@elasticmachine
Copy link

Package cloud_security_posture - 1.8.0-preview08 containing this change is available at https://epr.elastic.co/search?package=cloud_security_posture

@elasticmachine
Copy link

Package google_scc - 1.1.1 containing this change is available at https://epr.elastic.co/search?package=google_scc

@elasticmachine
Copy link

Package microsoft_defender_cloud - 1.1.1 containing this change is available at https://epr.elastic.co/search?package=microsoft_defender_cloud

@elasticmachine
Copy link

Package prisma_cloud - 1.1.1 containing this change is available at https://epr.elastic.co/search?package=prisma_cloud

@elasticmachine
Copy link

Package snyk - 1.20.1 containing this change is available at https://epr.elastic.co/search?package=snyk

@elasticmachine
Copy link

Package wiz - 1.1.1 containing this change is available at https://epr.elastic.co/search?package=wiz

@elasticmachine
Copy link

Package cloud_security_posture - 1.8.0 containing this change is available at https://epr.elastic.co/search?package=cloud_security_posture

@andrewkroh andrewkroh added Integration:aws AWS Integration:cloud_security_posture Security Posture Management Integration:google_scc Google Security Command Center labels Jul 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:aws AWS Integration:cloud_security_posture Security Posture Management Integration:google_scc Google Security Command Center Integration:microsoft_defender_cloud Microsoft Defender for Cloud Integration:prisma_cloud Palo Alto Prisma Cloud Integration:snyk Snyk Integration:wiz Wiz
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants