{
  "name": "ping_directory",
  "title": "PingDirectory",
  "version": "0.1.0",
  "release": "beta",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Collect logs from PingDirectory with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ping_directory/ping_directory-0.1.0.zip",
  "path": "/package/ping_directory/0.1.0",
  "icons": [
    {
      "src": "/img/ping_directory-logo.svg",
      "path": "/package/ping_directory/0.1.0/img/ping_directory-logo.svg",
      "title": "ping_directory logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.21 || ^9.4.6"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "authentication",
    "iam"
  ],
  "signature_path": "/epr/ping_directory/ping_directory-0.1.0.zip.sig",
  "format_version": "3.4.2",
  "readme": "/package/ping_directory/0.1.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/ping_directory-http-access-dashboard.png",
      "path": "/package/ping_directory/0.1.0/img/ping_directory-http-access-dashboard.png",
      "title": "HTTP Access Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ping_directory-audit-dashboard.png",
      "path": "/package/ping_directory/0.1.0/img/ping_directory-audit-dashboard.png",
      "title": "Audit Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ping_directory-ldap_access-dashboard.png",
      "path": "/package/ping_directory/0.1.0/img/ping_directory-ldap_access-dashboard.png",
      "title": "LDAP Access Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ping_directory-user-dashboard.png",
      "path": "/package/ping_directory/0.1.0/img/ping_directory-user-dashboard.png",
      "title": "User Directory Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ping_directory-group-dashboard.png",
      "path": "/package/ping_directory/0.1.0/img/ping_directory-group-dashboard.png",
      "title": "Group Directory Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ping_directory/0.1.0/LICENSE.txt",
    "/package/ping_directory/0.1.0/changelog.yml",
    "/package/ping_directory/0.1.0/manifest.yml",
    "/package/ping_directory/0.1.0/validation.yml",
    "/package/ping_directory/0.1.0/docs/README.md",
    "/package/ping_directory/0.1.0/img/ping_directory-audit-dashboard.png",
    "/package/ping_directory/0.1.0/img/ping_directory-group-dashboard.png",
    "/package/ping_directory/0.1.0/img/ping_directory-http-access-dashboard.png",
    "/package/ping_directory/0.1.0/img/ping_directory-ldap_access-dashboard.png",
    "/package/ping_directory/0.1.0/img/ping_directory-logo.svg",
    "/package/ping_directory/0.1.0/img/ping_directory-user-dashboard.png",
    "/package/ping_directory/0.1.0/data_stream/audit/manifest.yml",
    "/package/ping_directory/0.1.0/data_stream/audit/sample_event.json",
    "/package/ping_directory/0.1.0/data_stream/group/manifest.yml",
    "/package/ping_directory/0.1.0/data_stream/group/sample_event.json",
    "/package/ping_directory/0.1.0/data_stream/http_access/manifest.yml",
    "/package/ping_directory/0.1.0/data_stream/http_access/sample_event.json",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/manifest.yml",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/sample_event.json",
    "/package/ping_directory/0.1.0/data_stream/user/lifecycle.yml",
    "/package/ping_directory/0.1.0/data_stream/user/manifest.yml",
    "/package/ping_directory/0.1.0/data_stream/user/sample_event.json",
    "/package/ping_directory/0.1.0/kibana/dashboard/ping_directory-1ca066b0-8ff5-4518-820c-53f52e80a929.json",
    "/package/ping_directory/0.1.0/kibana/dashboard/ping_directory-35e0d479-ad96-46d3-b2c7-c34debf03606.json",
    "/package/ping_directory/0.1.0/kibana/dashboard/ping_directory-b2380ddf-991e-4c72-8fb4-abb3206db74d.json",
    "/package/ping_directory/0.1.0/kibana/dashboard/ping_directory-d475f863-3414-4288-a082-199a0991bb37.json",
    "/package/ping_directory/0.1.0/kibana/dashboard/ping_directory-f34ff331-41b1-4a64-a60f-5ef745aa78ac.json",
    "/package/ping_directory/0.1.0/kibana/search/ping_directory-01041f5b-637d-40c3-9b6a-43c8d77e3113.json",
    "/package/ping_directory/0.1.0/kibana/search/ping_directory-4387212b-bf20-4b29-8d54-03a18bf5a6c7.json",
    "/package/ping_directory/0.1.0/kibana/search/ping_directory-c56f9f5b-cb4f-4714-8346-e5fd858a7dea.json",
    "/package/ping_directory/0.1.0/data_stream/audit/fields/base-fields.yml",
    "/package/ping_directory/0.1.0/data_stream/audit/fields/beats.yml",
    "/package/ping_directory/0.1.0/data_stream/audit/fields/ecs.yml",
    "/package/ping_directory/0.1.0/data_stream/audit/fields/fields.yml",
    "/package/ping_directory/0.1.0/data_stream/group/fields/base-fields.yml",
    "/package/ping_directory/0.1.0/data_stream/group/fields/beats.yml",
    "/package/ping_directory/0.1.0/data_stream/group/fields/ecs.yml",
    "/package/ping_directory/0.1.0/data_stream/group/fields/fields.yml",
    "/package/ping_directory/0.1.0/data_stream/http_access/fields/base-fields.yml",
    "/package/ping_directory/0.1.0/data_stream/http_access/fields/beats.yml",
    "/package/ping_directory/0.1.0/data_stream/http_access/fields/ecs.yml",
    "/package/ping_directory/0.1.0/data_stream/http_access/fields/fields.yml",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/fields/base-fields.yml",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/fields/beats.yml",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/fields/ecs.yml",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/fields/fields.yml",
    "/package/ping_directory/0.1.0/data_stream/user/fields/base-fields.yml",
    "/package/ping_directory/0.1.0/data_stream/user/fields/beats.yml",
    "/package/ping_directory/0.1.0/data_stream/user/fields/ecs.yml",
    "/package/ping_directory/0.1.0/data_stream/user/fields/fields.yml",
    "/package/ping_directory/0.1.0/data_stream/user/fields/is-transform-source-true.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/manifest.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/transform.yml",
    "/package/ping_directory/0.1.0/data_stream/audit/agent/stream/filestream.yml.hbs",
    "/package/ping_directory/0.1.0/data_stream/audit/elasticsearch/ingest_pipeline/default.yml",
    "/package/ping_directory/0.1.0/data_stream/group/agent/stream/cel.yml.hbs",
    "/package/ping_directory/0.1.0/data_stream/group/elasticsearch/ingest_pipeline/default.yml",
    "/package/ping_directory/0.1.0/data_stream/http_access/agent/stream/filestream.yml.hbs",
    "/package/ping_directory/0.1.0/data_stream/http_access/elasticsearch/ingest_pipeline/default.yml",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/agent/stream/filestream.yml.hbs",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/agent/stream/udp.yml.hbs",
    "/package/ping_directory/0.1.0/data_stream/ldap_access/elasticsearch/ingest_pipeline/default.yml",
    "/package/ping_directory/0.1.0/data_stream/user/agent/stream/cel.yml.hbs",
    "/package/ping_directory/0.1.0/data_stream/user/elasticsearch/ilm/default_policy.json",
    "/package/ping_directory/0.1.0/data_stream/user/elasticsearch/ingest_pipeline/default.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/fields/base-fields.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/fields/beats.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/fields/ecs.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/fields/fields.yml",
    "/package/ping_directory/0.1.0/elasticsearch/transform/latest_user/fields/is-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ping_directory",
      "title": "PingDirectory",
      "description": "Collect PingDirectory logs via filestream, UDP and SCIM v2 REST API.",
      "inputs": [
        {
          "type": "filestream",
          "title": "Collect PingDirectory logs via Filestream",
          "description": "Collecting logs from PingDirectory via File."
        },
        {
          "type": "udp",
          "title": "Collect PingDirectory logs via UDP",
          "description": "Collecting logs from PingDirectory via UDP."
        },
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "url",
              "title": "URL",
              "description": "Base URL of the PingDirectory server. Example - https://pingdirectory.example.com:2443.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "bind_dn",
              "type": "text",
              "title": "Bind DN",
              "description": "Admin DN for authenticating to PingDirectory. Example - cn=Directory Manager.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "password",
              "type": "password",
              "title": "Password",
              "description": "Password for the admin Bind DN.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. Set verification_mode to none for self-signed certificates.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n# verification_mode: none\n"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server>:<port>.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "Collect PingDirectory log via SCIM v2 API",
          "description": "Collecting user and group logs from PingDirectory via SCIM v2 REST API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "beta"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ping_directory.audit",
      "title": "Audit",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "filestream",
          "vars": [
            {
              "name": "paths",
              "type": "text",
              "title": "Paths",
              "description": "A list of glob-based paths that will be crawled and fetched.",
              "multi": true,
              "required": true,
              "show_user": true,
              "default": [
                "/opt/pingdirectory/logs/audit*"
              ]
            },
            {
              "name": "max_lines",
              "type": "integer",
              "title": "Multiline Max Lines",
              "description": "Maximum number of lines to combine into a single multiline event for audit log entries.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 500
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ping_directory-audit"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "filestream.yml.hbs",
          "title": "Audit",
          "description": "Collect logs with filestream.",
          "enabled": false,
          "ingestion_method": "File"
        }
      ],
      "package": "ping_directory",
      "path": "audit"
    },
    {
      "type": "logs",
      "dataset": "ping_directory.group",
      "title": "Group",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between full sync requests to PingDirectory SCIM API. Supported units h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records fetched per page from PingDirectory SCIM API. Maps to the count parameter in SCIM pagination. Maximum supported value is 500.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 500
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "60s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ping_directory-group"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Collect PingDirectory Group logs via SCIM v2 API",
          "description": "Collect group logs from PingDirectory via SCIM v2 REST API.",
          "enabled": false,
          "ingestion_method": "API"
        }
      ],
      "package": "ping_directory",
      "path": "group"
    },
    {
      "type": "logs",
      "dataset": "ping_directory.http_access",
      "title": "HTTP Access",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "filestream",
          "vars": [
            {
              "name": "paths",
              "type": "text",
              "title": "Paths",
              "description": "A list of glob-based paths that will be crawled and fetched.",
              "multi": true,
              "required": true,
              "show_user": true,
              "default": [
                "/opt/pingdirectory/logs/http-access*"
              ]
            },
            {
              "name": "tz_offset",
              "type": "text",
              "title": "Timezone Offset",
              "description": "When interpreting syslog timestamps without a time zone, use this timezone offset. Datetimes recorded in logs are by default interpreted in relation to the timezone set up on the host where the agent is operating. Use this parameter to adjust the timezone offset when importing logs from a host in a different timezone so that datetimes are appropriately interpreted. Both a canonical ID (such as 'Europe/Amsterdam') and an HH:mm differential (such as \"-05:00\") are acceptable timezone formats.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ping_directory-http_access"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "filestream.yml.hbs",
          "title": "HTTP Access",
          "description": "Collect logs with filestream.",
          "enabled": false,
          "ingestion_method": "File"
        }
      ],
      "package": "ping_directory",
      "path": "http_access"
    },
    {
      "type": "logs",
      "dataset": "ping_directory.ldap_access",
      "title": "LDAP Access",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "udp",
          "vars": [
            {
              "name": "listen_address",
              "type": "text",
              "title": "Listen Address",
              "description": "The bind address to listen for UDP connections. Set to `0.0.0.0` to bind to all available interfaces.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "localhost"
            },
            {
              "name": "listen_port",
              "type": "integer",
              "title": "Listen Port",
              "description": "The UDP port number to listen on.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 9602
            },
            {
              "name": "udp_options",
              "type": "yaml",
              "title": "Custom UDP Options",
              "description": "Specify custom configuration options for the UDP input.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#max_message_size: 50KiB\n#timeout: 300s\n"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ping_directory-ldap_access"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "udp.yml.hbs",
          "title": "LDAP Access logs",
          "description": "Collect PingDirectory LDAP Access logs via syslog over UDP.",
          "enabled": false,
          "ingestion_method": "Network Protocol"
        },
        {
          "input": "filestream",
          "vars": [
            {
              "name": "paths",
              "type": "text",
              "title": "Paths",
              "description": "A list of glob-based paths that will be crawled and fetched.",
              "multi": true,
              "required": true,
              "show_user": true,
              "default": [
                "/opt/pingdirectory/logs/access*"
              ]
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ping_directory-ldap_access"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "filestream.yml.hbs",
          "title": "LDAP Access",
          "description": "Collect logs with filestream.",
          "enabled": false,
          "ingestion_method": "File"
        }
      ],
      "package": "ping_directory",
      "path": "ldap_access"
    },
    {
      "type": "logs",
      "dataset": "ping_directory.user",
      "ilm_policy": "logs-ping_directory.user-default_policy",
      "title": "User",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between full sync requests to PingDirectory SCIM API. Supported units h/m/s. Note - time-based filtering is not supported so full sync is performed every interval.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records fetched per page from PingDirectory SCIM API. Maps to the count parameter in SCIM pagination. Maximum supported value is 500.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 500
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "60s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ping_directory-user"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Collect PingDirectory User logs via SCIM v2 API",
          "description": "Collect user logs from PingDirectory via SCIM v2 REST API.",
          "enabled": false,
          "ingestion_method": "API"
        }
      ],
      "package": "ping_directory",
      "path": "user"
    }
  ]
}
