Skip to content

[ti_crowdstrike] Add Support of Deep Pagination in Intel Data Stream - #9200

Merged
efd6 merged 3 commits into
elastic:mainfrom
mohitjha-elastic:ti_crowdstrike-0.4.0
Feb 21, 2024
Merged

efd6 merged 3 commits into
elastic:mainfrom
mohitjha-elastic:ti_crowdstrike-0.4.0

Conversation

@mohitjha-elastic

@mohitjha-elastic mohitjha-elastic commented Feb 20, 2024 •

Copy link
Copy Markdown
Contributor

Type of change

  • Enhancement

What does this PR do?

Add Support of Deep Pagination in Intel Data Stream
Currently, the CrowdStrike Intel API limits the pagination to fetch the data upto 50,000 records only. If the sum of the offset and limit exceeds the value of 50000 then the API throws an error.
Using Deep Pagination, we can fetch all the data through the Intel Data Stream. Hence, Modified the data collection logic to perform pagination through the _marker in the filter instead of the offset and last_udpated to overcome the limit of Intel API.

A quick fix- Add the pull request URL in the changelog version for 0.3.0.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

All changes

  • Change follows the contributing guidelines
  • Supported versions of the monitoring target are documented
  • Supported operating systems are documented (if applicable)
  • Integration or System tests exist
  • Documentation exists
  • Fields follow ECS and naming conventions
  • At least a manual test with ES / Kibana / Agent has been performed.
  • Required Kibana version set to: ^8.11.0

How to test this PR locally

Clone integrations repo.
Install the elastic package locally.
Start the elastic stack using the elastic package.
Move to integrations/packages/ti_crowdstrike directory.
Run the following command to run tests.
elastic-package test -v

Related issues

Automated Test

test-ti_crowdstrike.log

@mohitjha-elastic
mohitjha-elastic requested a review from a team as a code owner February 20, 2024 11:25
Update the changelog entry for the version 0.3.0 too.
@jamiehynds jamiehynds added the Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] label Feb 20, 2024
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@jamiehynds jamiehynds added the Integration:ti_crowdstrike CrowdStrike Falcon Intelligence label Feb 20, 2024
@efd6

efd6 commented Feb 20, 2024

Copy link
Copy Markdown
Contributor

/test

1 similar comment
@efd6

efd6 commented Feb 20, 2024

Copy link
Copy Markdown
Contributor

/test

Comment thread packages/ti_crowdstrike/data_stream/intel/agent/stream/cel.yml.hbs Outdated
Comment thread packages/ti_crowdstrike/data_stream/intel/agent/stream/cel.yml.hbs Outdated
@efd6

efd6 commented Feb 20, 2024

Copy link
Copy Markdown
Contributor

Failure appears to be a builder issue.

Change the want_more condition, removed as.
Run system test.
@efd6

efd6 commented Feb 21, 2024

Copy link
Copy Markdown
Contributor

/test

@elastic-sonarqube

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No Coverage information No data about Coverage
No Duplication information No data about Duplication

See analysis details on SonarQube

@elasticmachine

Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

@efd6
efd6 merged commit 42f9d74 into elastic:main Feb 21, 2024
@elasticmachine

Copy link
Copy Markdown

Package ti_crowdstrike - 0.4.0 containing this change is available at https://epr.elastic.co/search?package=ti_crowdstrike

gizas pushed a commit that referenced this pull request Mar 13, 2024
…9200)

Currently, the CrowdStrike Intel API limits the pagination to fetch the data
up to 50,000 records only. If the sum of the offset and limit exceeds the
value of 50,000 then the API throws an error. Using Deep Pagination, we can
fetch all the data through the Intel Data Stream. So, modify the data
collection logic to perform pagination through the _marker in the filter
instead of the offset and last_updated to overcome the limit of Intel API.

Also fix the pull request URL in the changelog version for 0.3.0.
qcorporation pushed a commit that referenced this pull request Feb 3, 2025
…9200)

Currently, the CrowdStrike Intel API limits the pagination to fetch the data
up to 50,000 records only. If the sum of the offset and limit exceeds the
value of 50,000 then the API throws an error. Using Deep Pagination, we can
fetch all the data through the Intel Data Stream. So, modify the data
collection logic to perform pagination through the _marker in the filter
instead of the offset and last_updated to overcome the limit of Intel API.

Also fix the pull request URL in the changelog version for 0.3.0.
qcorporation pushed a commit that referenced this pull request Feb 4, 2025
…9200)

Currently, the CrowdStrike Intel API limits the pagination to fetch the data
up to 50,000 records only. If the sum of the offset and limit exceeds the
value of 50,000 then the API throws an error. Using Deep Pagination, we can
fetch all the data through the Intel Data Stream. So, modify the data
collection logic to perform pagination through the _marker in the filter
instead of the offset and last_updated to overcome the limit of Intel API.

Also fix the pull request URL in the changelog version for 0.3.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:ti_crowdstrike CrowdStrike Falcon Intelligence Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ti_crowdstrike: API throws an error for fetching more data through pagination

4 participants