{
  "name": "zoom",
  "title": "Zoom",
  "version": "1.21.0",
  "release": "ga",
  "description": "Collect logs from Zoom with Elastic Agent.",
  "type": "integration",
  "download": "/epr/zoom/zoom-1.21.0.zip",
  "path": "/package/zoom/1.21.0",
  "icons": [
    {
      "src": "/img/zoom_blue.svg",
      "path": "/package/zoom/1.21.0/img/zoom_blue.svg",
      "title": "Zoom",
      "size": "516x240",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.13.0"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "productivity_security"
  ],
  "signature_path": "/epr/zoom/zoom-1.21.0.zip.sig",
  "format_version": "3.0.2",
  "readme": "/package/zoom/1.21.0/docs/README.md",
  "license": "basic",
  "assets": [
    "/package/zoom/1.21.0/LICENSE.txt",
    "/package/zoom/1.21.0/changelog.yml",
    "/package/zoom/1.21.0/manifest.yml",
    "/package/zoom/1.21.0/validation.yml",
    "/package/zoom/1.21.0/docs/README.md",
    "/package/zoom/1.21.0/img/zoom_blue.svg",
    "/package/zoom/1.21.0/kibana/tags.yml",
    "/package/zoom/1.21.0/data_stream/webhook/manifest.yml",
    "/package/zoom/1.21.0/data_stream/webhook/sample_event.json",
    "/package/zoom/1.21.0/data_stream/webhook/fields/agent.yml",
    "/package/zoom/1.21.0/data_stream/webhook/fields/base-fields.yml",
    "/package/zoom/1.21.0/data_stream/webhook/fields/fields.yml",
    "/package/zoom/1.21.0/data_stream/webhook/agent/stream/http_endpoint.yml.hbs",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/account.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/chat_channel.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/chat_message.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/default.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/meeting.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/phone.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/recording.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/user.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/webinar.yml",
    "/package/zoom/1.21.0/data_stream/webhook/elasticsearch/ingest_pipeline/zoomroom.yml"
  ],
  "policy_templates": [
    {
      "name": "zoom",
      "title": "Zoom logs",
      "description": "Collect logs from Zoom instances",
      "inputs": [
        {
          "type": "http_endpoint",
          "title": "Collect Zoom logs via Webhook",
          "description": "Collecting logs from Zoom instances via Webhook"
        }
      ],
      "multiple": true
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "zoom.webhook",
      "title": "Zoom webhook logs",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "http_endpoint",
          "vars": [
            {
              "name": "listen_address",
              "type": "text",
              "title": "Listen Address",
              "description": "Bind address for the listener. Use 0.0.0.0 to listen on all interfaces.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "localhost"
            },
            {
              "name": "listen_port",
              "type": "integer",
              "title": "Listen Port",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 8181
            },
            {
              "name": "url",
              "type": "text",
              "title": "Webhook path",
              "description": "URL path where the webhook will accept requests.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "/zoom-webhook"
            },
            {
              "name": "crc_enabled",
              "type": "bool",
              "title": "Enable CRC validation",
              "description": "CRC validation is used by Zoom to verify the authenticity of a webhook endpoint. See [Validate your webhook endpoint](https://developers.zoom.us/docs/api/rest/webhook-reference/#validate-your-webhook-endpoint) for more information.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "crc_secret",
              "type": "password",
              "title": "Zoom Secret Token",
              "description": "Secret token provided by Zoom when the webhook was configured. It is used for the CRC validation of the webhook endpoint.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "secret_header",
              "type": "text",
              "title": "Zoom Custom Header",
              "description": "Custom header used to validate the authenticity of incoming Zoom POST requests. It should be created by the user when configuring the webhook on Zoom. See [Verify webhook events](https://developers.zoom.us/docs/api/rest/webhook-reference/#custom-header) for more information.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "Authorization"
            },
            {
              "name": "secret_value",
              "type": "password",
              "title": "Zoom Custom Header value",
              "description": "Custom header value used to validate the authenticity of incoming Zoom POST requests. It should be created by the user when configuring the webhook on Zoom. See [Verify webhook events](https://developers.zoom.us/docs/api/rest/webhook-reference/#custom-header) for more information.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "TLS",
              "description": "Options for enabling TLS for the listening webhook endpoint. Zoom requires webhooks listen on HTTPS. You must either provide a valid TLS certificate or use a reverse proxy in front of the integration. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html) for a list of all options.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "enabled: false\ncertificate: \"/etc/pki/client/cert.pem\"\nkey: \"/etc/pki/client/cert.key\"\n"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "zoom-webhook",
                "forwarded"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            }
          ],
          "template_path": "http_endpoint.yml.hbs",
          "title": "Zoom webhook logs",
          "description": "Collect Zoom logs via Webhook",
          "enabled": true,
          "ingestion_method": "Webhook"
        }
      ],
      "package": "zoom",
      "path": "webhook"
    }
  ]
}
