-
Notifications
You must be signed in to change notification settings - Fork 159
Analyzer support for CrowdStrike and SentinelOne #2306
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🔍 Preview links for changed docs |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm!
@natasha-moore-elastic I think we need to specify a little bit more on the Crowdstrike side, not sure if all the integration types are supported. I think only Crowdstrike Event Stream and Falcon Data Replicator. @tomsonpl can you confirm this? what is your opinion on this one? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Specify the Crowdstrike mode of integration that supports analyzer. I think it is only supported with Crowdstrike Event Stream and Falcon Data Replicar but better confirm with @tomsonpl
Hey @raqueltabuyo @natasha-moore-elastic 👋 Although it's still the same integration, I think we might mention that analyzer needs process data that comes from either FDR or Falcon Logs. |
Thanks @tomsonpl! I've added this info now, but let me know if we need to describe this in more detail. |
Hey @natasha-moore-elastic SIEM Connector won't help much here, after speaking with @tomsonpl , we think instead we can have the following:
|
Thanks @raqueltabuyo, I've updated to your suggested wording 👍 |
Contributes to #2024. Updates the visual event analyzer docs to document support for analyzing events from CrowdStrike and SentinelOne integrations.
Preview: Visual event analyzer
8.x PR: elastic/security-docs#6989