Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions packages/ti_misp/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@

The MISP integration uses the [REST API from the running MISP instance](https://www.circl.lu/doc/misp/automation/#automation-api) to retrieve indicators and Threat Intelligence.

## Agentless Enabled Integration

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to [Agentless integrations](https://www.elastic.co/guide/en/serverless/current/security-agentless-integrations.html) and the [Agentless integrations FAQ](https://www.elastic.co/guide/en/serverless/current/agentless-integration-troubleshooting.html).
Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

## Logs

### Threat
Expand Down
5 changes: 5 additions & 0 deletions packages/ti_misp/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.44.0"
changes:
- description: Enable Agentless deployment.
type: enhancement
link: https://github.com/elastic/integrations/pull/19702
- version: "1.43.1"
changes:
- description: Disable `X-Rate-Limit-*` response header parsing by default. The agent went DEGRADED on MISP instances that do not have rate limiting enabled. A new `enable_rate_limit_headers` toggle (default off) lets users opt in when their MISP role enforces rate limits.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,9 @@ processors:
description: 'Renames the original `message` field to `event.original` to store a copy of the original message. The `event.original` field is not touched if the document already has one; it may happen when Logstash sends the document.'
- remove:
field: message
tag: remove_message
ignore_missing: true
if: 'ctx.event?.original != null'
if: ctx.event?.original != null
description: 'The `message` field is no longer required if the document has an `event.original` field.'
- json:
field: event.original
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,9 @@ processors:
description: 'Renames the original `message` field to `event.original` to store a copy of the original message. The `event.original` field is not touched if the document already has one; it may happen when Logstash sends the document.'
- remove:
field: message
tag: remove_message
ignore_missing: true
if: 'ctx.event?.original != null'
if: ctx.event?.original != null
description: 'The `message` field is no longer required if the document has an `event.original` field.'
- json:
field: event.original
Expand Down
5 changes: 5 additions & 0 deletions packages/ti_misp/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@

The MISP integration uses the [REST API from the running MISP instance](https://www.circl.lu/doc/misp/automation/#automation-api) to retrieve indicators and Threat Intelligence.

## Agentless Enabled Integration

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to [Agentless integrations](https://www.elastic.co/guide/en/serverless/current/security-agentless-integrations.html) and the [Agentless integrations FAQ](https://www.elastic.co/guide/en/serverless/current/agentless-integration-troubleshooting.html).
Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

## Logs

### Threat
Expand Down
15 changes: 12 additions & 3 deletions packages/ti_misp/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: ti_misp
title: MISP
version: "1.43.1"
version: "1.44.0"
description: Ingest threat intelligence indicators from MISP platform with Elastic Agent.
type: integration
format_version: "3.0.2"
format_version: "3.3.2"
categories:
- security
- threat_intel
conditions:
kibana:
version: "^8.13.0 || ^9.0.0"
version: "^8.19.4 || ~9.0.7 || ^9.1.4"
icons:
- src: /img/misp.svg
title: MISP
Expand All @@ -28,6 +28,15 @@ policy_templates:
- name: ti_misp
title: MISP
description: Ingest threat intelligence indicators from MISP platform with Elastic Agent.
deployment_modes:
default:
enabled: true
agentless:
enabled: true
release: beta
organization: security
division: engineering
team: security-service-integrations
inputs:
- type: httpjson
title: "Ingest threat intelligence indicators from MISP platform with Elastic Agent."
Expand Down
Loading