Skip to content

Commit cabac75

Browse files
[8.19] XSOAR Connector (#212049) (#224698)
# Backport This will backport the following commits from `main` to `8.19`: - [XSOAR Connector (#212049)](#212049) <!--- Backport version: 10.0.1 --> ### Questions ? Please refer to the [Backport tool documentation](https://github.com/sorenlouv/backport) <!--BACKPORT [{"author":{"name":"Brijesh Khunt","email":"[email protected]"},"sourceCommit":{"committedDate":"2025-06-20T12:50:07Z","message":"XSOAR Connector (#212049)\n\n## Summary\n\nXSOAR action connector, enabling users to send alerts generated by the\nrule detection engine to Palo Alto XSOAR for automation and remediation.\n\n### **create connector**\n\n![xsoar-connector](https://github.com/user-attachments/assets/14d9791b-0242-42b5-b9e4-975d7f6826cc)\n\n### **test connector**\n1. **test page**\n\n![xsoar-params-test](https://github.com/user-attachments/assets/2bdd3b79-7f5f-4d52-836b-f458c390e55c)\n\n2. **select playbook**\n\n![xsoar-select-playbook](https://github.com/user-attachments/assets/23787b24-31b0-4f56-b451-0e8b42c79797)\n\n### Checklist\n\nCheck the PR satisfies following conditions. \n\nReviewers should verify this PR satisfies this list as well.\n\n- [x] Any text added follows [EUI's writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing), uses\nsentence case text and includes [i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n- [ ]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas added for features that require explanation or tutorials\n- [x] [Unit or functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere updated or added to match the most common scenarios\n- [x] If a plugin configuration key changed, check if it needs to be\nallowlisted in the cloud and added to the [docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n- [x] This was checked for breaking HTTP API changes, and any breaking\nchanges have been approved by the breaking-change committee. The\n`release_note:breaking` label should be applied in these situations.\n- [x] [Flaky Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1) was\nused on any tests changed\n- [x] The PR description includes the appropriate Release Notes section,\nand the correct `release_note:*` label is applied per the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n\n### For maintainers\n\n- [ ] This was checked for breaking API changes and was [labeled\nappropriately](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n\n---------\n\nCo-authored-by: kibanamachine <[email protected]>\nCo-authored-by: Sergi Massaneda <[email protected]>\nCo-authored-by: Nastasha Solomon <[email protected]>\nCo-authored-by: Elastic Machine <[email protected]>","sha":"3fcdc062fa0867ffa6502823e2b31f8f2ad99ac9","branchLabelMapping":{"^v9.1.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["Team:ResponseOps","Team: SecuritySolution","release_note:feature","backport:version","v9.1.0","v8.19.0"],"title":"XSOAR Connector","number":212049,"url":"https://github.com/elastic/kibana/pull/212049","mergeCommit":{"message":"XSOAR Connector (#212049)\n\n## Summary\n\nXSOAR action connector, enabling users to send alerts generated by the\nrule detection engine to Palo Alto XSOAR for automation and remediation.\n\n### **create connector**\n\n![xsoar-connector](https://github.com/user-attachments/assets/14d9791b-0242-42b5-b9e4-975d7f6826cc)\n\n### **test connector**\n1. **test page**\n\n![xsoar-params-test](https://github.com/user-attachments/assets/2bdd3b79-7f5f-4d52-836b-f458c390e55c)\n\n2. **select playbook**\n\n![xsoar-select-playbook](https://github.com/user-attachments/assets/23787b24-31b0-4f56-b451-0e8b42c79797)\n\n### Checklist\n\nCheck the PR satisfies following conditions. \n\nReviewers should verify this PR satisfies this list as well.\n\n- [x] Any text added follows [EUI's writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing), uses\nsentence case text and includes [i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n- [ ]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas added for features that require explanation or tutorials\n- [x] [Unit or functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere updated or added to match the most common scenarios\n- [x] If a plugin configuration key changed, check if it needs to be\nallowlisted in the cloud and added to the [docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n- [x] This was checked for breaking HTTP API changes, and any breaking\nchanges have been approved by the breaking-change committee. The\n`release_note:breaking` label should be applied in these situations.\n- [x] [Flaky Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1) was\nused on any tests changed\n- [x] The PR description includes the appropriate Release Notes section,\nand the correct `release_note:*` label is applied per the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n\n### For maintainers\n\n- [ ] This was checked for breaking API changes and was [labeled\nappropriately](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n\n---------\n\nCo-authored-by: kibanamachine <[email protected]>\nCo-authored-by: Sergi Massaneda <[email protected]>\nCo-authored-by: Nastasha Solomon <[email protected]>\nCo-authored-by: Elastic Machine <[email protected]>","sha":"3fcdc062fa0867ffa6502823e2b31f8f2ad99ac9"}},"sourceBranch":"main","suggestedTargetBranches":["8.19"],"targetPullRequestStates":[{"branch":"main","label":"v9.1.0","branchLabelMappingKey":"^v9.1.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/212049","number":212049,"mergeCommit":{"message":"XSOAR Connector (#212049)\n\n## Summary\n\nXSOAR action connector, enabling users to send alerts generated by the\nrule detection engine to Palo Alto XSOAR for automation and remediation.\n\n### **create connector**\n\n![xsoar-connector](https://github.com/user-attachments/assets/14d9791b-0242-42b5-b9e4-975d7f6826cc)\n\n### **test connector**\n1. **test page**\n\n![xsoar-params-test](https://github.com/user-attachments/assets/2bdd3b79-7f5f-4d52-836b-f458c390e55c)\n\n2. **select playbook**\n\n![xsoar-select-playbook](https://github.com/user-attachments/assets/23787b24-31b0-4f56-b451-0e8b42c79797)\n\n### Checklist\n\nCheck the PR satisfies following conditions. \n\nReviewers should verify this PR satisfies this list as well.\n\n- [x] Any text added follows [EUI's writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing), uses\nsentence case text and includes [i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n- [ ]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas added for features that require explanation or tutorials\n- [x] [Unit or functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere updated or added to match the most common scenarios\n- [x] If a plugin configuration key changed, check if it needs to be\nallowlisted in the cloud and added to the [docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n- [x] This was checked for breaking HTTP API changes, and any breaking\nchanges have been approved by the breaking-change committee. The\n`release_note:breaking` label should be applied in these situations.\n- [x] [Flaky Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1) was\nused on any tests changed\n- [x] The PR description includes the appropriate Release Notes section,\nand the correct `release_note:*` label is applied per the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n\n### For maintainers\n\n- [ ] This was checked for breaking API changes and was [labeled\nappropriately](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n\n---------\n\nCo-authored-by: kibanamachine <[email protected]>\nCo-authored-by: Sergi Massaneda <[email protected]>\nCo-authored-by: Nastasha Solomon <[email protected]>\nCo-authored-by: Elastic Machine <[email protected]>","sha":"3fcdc062fa0867ffa6502823e2b31f8f2ad99ac9"}},{"branch":"8.19","label":"v8.19.0","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"}]}] BACKPORT--> Co-authored-by: Brijesh Khunt <[email protected]>
1 parent b27e0ed commit cabac75

File tree

38 files changed

+3621
-2
lines changed

38 files changed

+3621
-2
lines changed

docs/docset.yml

Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
project: 'Kibana docs'
2+
products:
3+
- id: kibana
4+
exclude:
5+
- settings-gen/readme.md
6+
- development/plugins/expressions/public/kibana-plugin-plugins-expressions-public.createdefaultinspectoradapters.md
7+
cross_links:
8+
- apm-agent-nodejs
9+
- apm-agent-rum-js
10+
- docs-content
11+
- ecs
12+
- elasticsearch
13+
toc:
14+
- toc: reference
15+
- toc: release-notes
16+
- toc: extend
17+
subs:
18+
version: "9.0.0"
19+
branch: "9.0"
20+
ecloud: "Elastic Cloud"
21+
ech: "Elastic Cloud Hosted"
22+
ess: "Elasticsearch Service"
23+
ece: "Elastic Cloud Enterprise"
24+
serverless-full: "Elastic Cloud Serverless"
25+
security-app: "Elastic Security app"
26+
stack-manage-app: "Stack Management"
27+
stack-monitor-app: "Stack Monitoring"
28+
rules-ui: "Rules"
29+
connectors-ui: "Connectors"
30+
connectors-feature: "Actions and Connectors"
31+
hosted-ems: "Elastic Maps Server"
32+
data-sources: "data views"
33+
agent: "Elastic Agent"
34+
agents: "Elastic Agents"
35+
fleet: "Fleet"
36+
fleet-server: "Fleet Server"
37+
package-manager: "Elastic Package Manager"
38+
stack: "Elastic Stack"
39+
es: "Elasticsearch"
40+
kib: "Kibana"
41+
ls: "Logstash"
42+
security-features: "security features"
43+
stack-security-features: "Elastic Stack security features"
44+
endpoint-sec: "Endpoint Security"
45+
swimlane: "Swimlane"
46+
sn: "ServiceNow"
47+
sn-itsm: "ServiceNow ITSM"
48+
sn-itom: "ServiceNow ITOM"
49+
sn-sir: "ServiceNow SecOps"
50+
ibm-r: "IBM Resilient"
51+
webhook: "Webhook"
52+
webhook-cm: "Webhook - Case Management"
53+
opsgenie: "Opsgenie"
54+
bedrock: "Amazon Bedrock"
55+
gemini: "Google Gemini"
56+
hive: "TheHive"
57+
xsoar: "XSOAR"
58+
report-features: "reporting features"
59+
ml: "machine learning"
60+
ccs: "cross-cluster search"
61+
anomaly-job: "anomaly detection job"
62+
observability: "Observability"
63+
kib-repo: "https://github.com/elastic/kibana/"
64+
kib-pull: "https://github.com/elastic/kibana/pull/"
Lines changed: 124 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
1+
---
2+
mapped_pages:
3+
- https://www.elastic.co/guide/en/kibana/current/action-types.html
4+
navigation_title: Connectors
5+
applies_to:
6+
serverless: ga
7+
stack: ga
8+
---
9+
# Kibana connectors [action-types]
10+
11+
Connectors provide a central place to store connection information for services and integrations with Elastic or third party systems.
12+
Actions are instantiations of a connector that are linked to rules and run as background tasks on the {{kib}} server when rule conditions are met.
13+
{{kib}} provides the following types of connectors:
14+
15+
* [{{bedrock}}](/reference/connectors-kibana/bedrock-action-type.md): Send a request to {{bedrock}}.
16+
* [Cases](/reference/connectors-kibana/cases-action-type.md): Add alerts to cases.
17+
* [CrowdStrike](/reference/connectors-kibana/crowdstrike-action-type.md): Send a request to CrowdStrike.
18+
* [D3 Security](/reference/connectors-kibana/d3security-action-type.md): Send a request to D3 Security.
19+
* [{{gemini}}](/reference/connectors-kibana/gemini-action-type.md): Send a request to {{gemini}}.
20+
* [Elastic Managed LLM](/reference/connectors-kibana/elastic-managed-llm.md): Send a request to Elastic Managed LLM.
21+
* [Email](/reference/connectors-kibana/email-action-type.md): Send email from your server.
22+
* [{{ibm-r}}](/reference/connectors-kibana/resilient-action-type.md): Create an incident in {{ibm-r}}.
23+
* [Index](/reference/connectors-kibana/index-action-type.md): Index data into Elasticsearch.
24+
* [Jira](/reference/connectors-kibana/jira-action-type.md): Create an incident in Jira.
25+
* [Microsoft Defender for Endpoint](/reference/connectors-kibana/defender-action-type.md): Send requests to Microsoft Defender-enrolled hosts.
26+
* [Microsoft Teams](/reference/connectors-kibana/teams-action-type.md): Send a message to a Microsoft Teams channel.
27+
* [Observability AI Assistant](/reference/connectors-kibana/obs-ai-assistant-action-type.md): Add AI-driven insights and custom actions to your workflow.
28+
* [OpenAI](/reference/connectors-kibana/openai-action-type.md): Send a request to OpenAI.
29+
* [{{opsgenie}}](/reference/connectors-kibana/opsgenie-action-type.md): Create or close an alert in {{opsgenie}}.
30+
* [PagerDuty](/reference/connectors-kibana/pagerduty-action-type.md): Send an event in PagerDuty.
31+
* [SentinelOne](/reference/connectors-kibana/sentinelone-action-type.md): Send a request to SentinelOne.
32+
* [ServerLog](/reference/connectors-kibana/server-log-action-type.md): Add a message to a Kibana log.
33+
* [{{sn-itsm}}](/reference/connectors-kibana/servicenow-action-type.md): Create an incident in {{sn}}.
34+
* [{{sn-sir}}](/reference/connectors-kibana/servicenow-sir-action-type.md): Create a security incident in {{sn}}.
35+
* [{{sn-itom}}](/reference/connectors-kibana/servicenow-itom-action-type.md): Create an event in {{sn}}.
36+
* [Slack](/reference/connectors-kibana/slack-action-type.md): Send a message to a Slack channel or user.
37+
* [{{swimlane}}](/reference/connectors-kibana/swimlane-action-type.md): Create an incident in {{swimlane}}.
38+
* [{{hive}}](/reference/connectors-kibana/thehive-action-type.md): Create cases and alerts in {{hive}}.
39+
* [Tines](/reference/connectors-kibana/tines-action-type.md): Send events to a Tines Story.
40+
* [Torq](/reference/connectors-kibana/torq-action-type.md): Trigger a Torq workflow.
41+
* [{{webhook}}](/reference/connectors-kibana/webhook-action-type.md): Send a request to a web service.
42+
* [{{webhook-cm}}](/reference/connectors-kibana/cases-webhook-action-type.md): Send a request to a Case Management web service.
43+
* [xMatters](/reference/connectors-kibana/xmatters-action-type.md): Send actionable alerts to on-call xMatters resources.
44+
* [{{xsoar}}](/reference/connectors-kibana/xsoar-action-type.md): Create an incident in Cortex {{xsoar}}.
45+
46+
::::{note}
47+
Some connector types are paid commercial features, while others are free. For a comparison of the Elastic subscription levels, go to [the subscription page](https://www.elastic.co/subscriptions).
48+
49+
::::
50+
51+
52+
53+
## Managing connectors [connector-management]
54+
55+
Rules use connectors to route actions to different destinations like log files, ticketing systems, and messaging tools. While each {{kib}} app can offer their own types of rules, they typically share connectors. **{{stack-manage-app}} > {{connectors-ui}}** offers a central place to view and manage all the connectors in the current space.
56+
57+
% TO DO: Use `:class: screenshot`
58+
![Example connector listing in the {{rules-ui}} UI](images/connector-listing.png)
59+
60+
61+
## Required permissions [_required_permissions_2]
62+
63+
Access to connectors is granted based on your privileges to alerting-enabled features. For more information, go to [Security](docs-content://explore-analyze/alerts-cases/alerts/alerting-setup.md#alerting-security).
64+
65+
66+
## Connector networking configuration [_connector_networking_configuration]
67+
68+
Use the [action configuration settings](/reference/configuration-reference/alerting-settings.md#action-settings) to customize connector networking configurations, such as proxies, certificates, or TLS settings. You can set configurations that apply to all your connectors or use `xpack.actions.customHostSettings` to set per-host configurations.
69+
70+
71+
## Connector list [connectors-list]
72+
73+
In **{{stack-manage-app}} > {{connectors-ui}}**, you can find a list of the connectors in the current space. You can use the search bar to find specific connectors by name and type. The **Type** dropdown also enables you to filter to a subset of connector types.
74+
75+
% TO DO: Use `:class: screenshot`
76+
![Filtering the connector list by types of connectors](images/connector-filter-by-type.png)
77+
78+
You can delete individual connectors using the trash icon. Alternatively, select multiple connectors and delete them in bulk using the **Delete** button.
79+
80+
% TO DO: Use `:class: screenshot`
81+
![Deleting connectors individually or in bulk](images/connector-delete.png)
82+
83+
::::{note}
84+
You can delete a connector even if there are still actions referencing it. When this happens the action will fail to run and errors appear in the {{kib}} logs.
85+
86+
::::
87+
88+
89+
90+
## Creating a new connector [creating-new-connector]
91+
92+
New connectors can be created with the **Create connector** button, which guides you to select the type of connector and configure its properties.
93+
94+
% TO DO: Use `:class: screenshot`
95+
![Connector select type](images/connector-select-type.png)
96+
97+
After you create a connector, it is available for use any time you set up an action in the current space.
98+
99+
For out-of-the-box and standardized connectors, refer to [preconfigured connectors](/reference/connectors-kibana/pre-configured-connectors.md).
100+
101+
::::{tip}
102+
You can also manage connectors as resources with the [Elasticstack provider](https://registry.terraform.io/providers/elastic/elasticstack/latest) for Terraform. For more details, refer to the [elasticstack_kibana_action_connector](https://registry.terraform.io/providers/elastic/elasticstack/latest/docs/resources/kibana_action_connector) resource.
103+
::::
104+
105+
106+
107+
## Importing and exporting connectors [importing-and-exporting-connectors]
108+
109+
To import and export connectors, use the [Saved Objects Management UI](docs-content://explore-analyze/find-and-organize/saved-objects.md).
110+
111+
% TO DO: Use `:class: screenshot`
112+
![Connectors import banner](images/connectors-import-banner.png)
113+
114+
If a connector is missing sensitive information after the import, a **Fix** button appears in **{{connectors-ui}}**.
115+
116+
% TO DO: Use `:class: screenshot`
117+
![Connectors with missing secrets](images/connectors-with-missing-secrets.png)
118+
119+
120+
## Monitoring connectors [monitoring-connectors]
121+
122+
The [Task Manager health API](docs-content://deploy-manage/monitor/kibana-task-manager-health-monitoring.md) helps you understand the performance of all tasks in your environment. However, if connectors fail to run, they will report as successful to Task Manager. The failure stats will not accurately depict the performance of connectors.
123+
124+
For more information on connector successes and failures, refer to the [Event log index](docs-content://explore-analyze/alerts-cases/alerts/event-log-index.md).
Lines changed: 80 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
---
2+
navigation_title: "{{xsoar}}"
3+
mapped_pages:
4+
- https://www.elastic.co/guide/en/kibana/current/xsoar-action-type.html
5+
---
6+
7+
# {{xsoar}} connector and action [xsoar-action-type]
8+
9+
10+
{{xsoar}} connector uses the [{{xsoar}} REST API](https://cortex-panw.stoplight.io/docs/cortex-xsoar-8/m0qlgh9inh4vk-create-or-update-an-incident) to create Cortex {{xsoar}} incidents.
11+
12+
13+
## Create connectors in {{kib}} [define-xsoar-ui]
14+
15+
You can create connectors in **{{stack-manage-app}} > {{connectors-ui}}** or as needed when you’re creating a rule. For example:
16+
17+
% TO DO: Use `:class: screenshot`
18+
![XSOAR connector](../images/xsoar-connector.png)
19+
20+
21+
### Connector configuration [xsoar-connector-configuration]
22+
23+
{{xsoar}} connectors have the following configuration properties:
24+
25+
Name
26+
: The name of the connector.
27+
28+
URL
29+
: The {{xsoar}} instance URL.
30+
31+
API key
32+
: The {{xsoar}} API key for authentication.
33+
34+
::::{note}
35+
If you do not have an API key, refer to [Create a new API key](https://cortex-panw.stoplight.io/docs/cortex-xsoar-8/t09y7hrb5d14m-create-a-new-api-key) to make one for your {{xsoar}} instance.
36+
::::
37+
38+
API key id
39+
: The {{xsoar}} API key ID for authentication. (Mandatory for cloud instance users.)
40+
41+
42+
## Test connectors [xsoar-action-configuration]
43+
44+
You can test connectors as you’re creating or editing the connector in {{kib}}. For example:
45+
46+
% TO DO: Use `:class: screenshot`
47+
![XSOAR params test](../images/xsoar-params-test.png)
48+
49+
{{xsoar}} actions have the following configuration properties.
50+
51+
Name
52+
: The incident name.
53+
54+
Playbook
55+
: The playbook to associate with the incident.
56+
57+
Start investigation
58+
: If turned on, will automatically start the investigation process after the incident is created.
59+
60+
Severity
61+
: The severity of the incident. Can be `Unknown`, `Informational`, `Low`, `Medium`, `High` or `Critical`.
62+
63+
::::{note}
64+
Turn on `Keep severity from rule` to create an incident that inherits the rule's severity.
65+
::::
66+
67+
Body
68+
: A JSON payload that includes additional parameters to be included in the API request.
69+
70+
```json
71+
{
72+
"details": "This is an example incident",
73+
"type": "Unclassified"
74+
}
75+
```
76+
77+
78+
## Connector networking configuration [xsoar-connector-networking-configuration]
79+
80+
Use the [Action configuration settings](/reference/configuration-reference/alerting-settings.md#action-settings) to customize connector networking configurations, such as proxies, certificates, or TLS settings. You can set configurations that apply to all your connectors or use `xpack.actions.customHostSettings` to set per-host configurations.
75.9 KB
Loading
46.2 KB
Loading

docs/reference/toc.yml

Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
project: 'Kibana reference'
2+
toc:
3+
- file: index.md
4+
- file: kibana-accessibility-statement.md
5+
- file: configuration-reference.md
6+
children:
7+
- file: cloud/elastic-cloud-kibana-settings.md
8+
- file: configuration-reference/general-settings.md
9+
- file: configuration-reference/ai-assistant-settings.md
10+
- file: configuration-reference/alerting-settings.md
11+
- file: configuration-reference/apm-settings.md
12+
- file: configuration-reference/banner-settings.md
13+
- file: configuration-reference/cases-settings.md
14+
- file: configuration-reference/fleet-settings.md
15+
- file: configuration-reference/internationalization-settings.md
16+
- file: configuration-reference/logging-settings.md
17+
- file: configuration-reference/logs-settings.md
18+
- file: configuration-reference/map-settings.md
19+
- file: configuration-reference/metrics-settings.md
20+
- file: configuration-reference/monitoring-settings.md
21+
- file: configuration-reference/reporting-settings.md
22+
- file: configuration-reference/search-sessions-settings.md
23+
- file: configuration-reference/security-settings.md
24+
- file: configuration-reference/spaces-settings.md
25+
- file: configuration-reference/task-manager-settings.md
26+
- file: configuration-reference/telemetry-settings.md
27+
- file: configuration-reference/url-drilldown-settings.md
28+
- file: advanced-settings.md
29+
- file: kibana-audit-events.md
30+
- file: connectors-kibana.md
31+
children:
32+
- file: connectors-kibana/bedrock-action-type.md
33+
- file: connectors-kibana/cases-action-type.md
34+
- file: connectors-kibana/crowdstrike-action-type.md
35+
- file: connectors-kibana/d3security-action-type.md
36+
- file: connectors-kibana/elastic-managed-llm.md
37+
- file: connectors-kibana/email-action-type.md
38+
- file: connectors-kibana/gemini-action-type.md
39+
- file: connectors-kibana/resilient-action-type.md
40+
- file: connectors-kibana/index-action-type.md
41+
- file: connectors-kibana/jira-action-type.md
42+
- file: connectors-kibana/defender-action-type.md
43+
- file: connectors-kibana/teams-action-type.md
44+
- file: connectors-kibana/obs-ai-assistant-action-type.md
45+
- file: connectors-kibana/openai-action-type.md
46+
- file: connectors-kibana/opsgenie-action-type.md
47+
- file: connectors-kibana/pagerduty-action-type.md
48+
- file: connectors-kibana/sentinelone-action-type.md
49+
- file: connectors-kibana/server-log-action-type.md
50+
- file: connectors-kibana/servicenow-action-type.md
51+
- file: connectors-kibana/servicenow-sir-action-type.md
52+
- file: connectors-kibana/servicenow-itom-action-type.md
53+
- file: connectors-kibana/swimlane-action-type.md
54+
- file: connectors-kibana/slack-action-type.md
55+
- file: connectors-kibana/thehive-action-type.md
56+
- file: connectors-kibana/tines-action-type.md
57+
- file: connectors-kibana/torq-action-type.md
58+
- file: connectors-kibana/webhook-action-type.md
59+
- file: connectors-kibana/cases-webhook-action-type.md
60+
- file: connectors-kibana/xmatters-action-type.md
61+
- file: connectors-kibana/xsoar-action-type.md
62+
- file: connectors-kibana/pre-configured-connectors.md
63+
- file: kibana-plugins.md
64+
- file: commands.md
65+
children:
66+
- file: commands/kibana-encryption-keys.md
67+
- file: commands/kibana-verification-code.md
68+
- file: osquery-exported-fields.md
69+
- file: osquery-manager-prebuilt-packs.md

0 commit comments

Comments
 (0)