-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SIEM][CEF] Add support for Check Point devices #16907
Merged
Merged
Commits on Mar 18, 2020
-
Make CEF key name mapping case-insensitive
There's some case inconsistency in CEF docs (i.e. C6a4Label). Better to ignore case when mapping keys to full names.
Configuration menu - View commit details
-
Copy full SHA for 5aed151 - Browse repository at this point
Copy the full SHA 5aed151View commit details -
Add missing custom CEF extensions
This adds: - `deviceCustomIPv6Address2(Label)`: Only 1, 3 and 4 were expected. - `flexNumber[12](Label)`: These two alternative custom numbers were dropped after V23 of the spec, but still used by some vendors. [Maybe unnecessary] changes: - Changed the case of `DeviceCustomNumber2` from uppercase as documented) to lowercase to align with the other fields.
Configuration menu - View commit details
-
Copy full SHA for 9639d3a - Browse repository at this point
Copy the full SHA 9639d3aView commit details -
CEF module: Support Check Point devices
This adds a new ingest pipeline and fields to populate from Check Point CEF logs. Closes elastic#16041
Configuration menu - View commit details
-
Copy full SHA for b2210e7 - Browse repository at this point
Copy the full SHA b2210e7View commit details -
Configuration menu - View commit details
-
Copy full SHA for e3f9f86 - Browse repository at this point
Copy the full SHA e3f9f86View commit details -
Configuration menu - View commit details
-
Copy full SHA for 92a30c0 - Browse repository at this point
Copy the full SHA 92a30c0View commit details -
Configuration menu - View commit details
-
Copy full SHA for aae6071 - Browse repository at this point
Copy the full SHA aae6071View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2db8b7a - Browse repository at this point
Copy the full SHA 2db8b7aView commit details -
Configuration menu - View commit details
-
Copy full SHA for ab3418c - Browse repository at this point
Copy the full SHA ab3418cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 98f9f17 - Browse repository at this point
Copy the full SHA 98f9f17View commit details -
Configuration menu - View commit details
-
Copy full SHA for d17acce - Browse repository at this point
Copy the full SHA d17acceView commit details -
Configuration menu - View commit details
-
Copy full SHA for 81a7702 - Browse repository at this point
Copy the full SHA 81a7702View commit details
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.