Skip to content

Commit dcecfb5

Browse files
kibanamachinelcawl
andauthored
[9.0] [DOCS] Update CrowdStrike and SentinelOne connectors (elastic#219887) (elastic#220564)
# Backport This will backport the following commits from `main` to `9.0`: - [[DOCS] Update CrowdStrike and SentinelOne connectors (elastic#219887)](elastic#219887) <!--- Backport version: 9.6.6 --> ### Questions ? Please refer to the [Backport tool documentation](https://github.com/sorenlouv/backport) <!--BACKPORT [{"author":{"name":"Lisa Cawley","email":"[email protected]"},"sourceCommit":{"committedDate":"2025-05-08T18:34:40Z","message":"[DOCS] Update CrowdStrike and SentinelOne connectors (elastic#219887)","sha":"f3115c6746fe071672911a2e7f74b03bff10b209","branchLabelMapping":{"^v9.1.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:skip","Team:ResponseOps","docs","backport:version","v9.1.0","v8.19.0","v8.18.2","v9.0.2"],"title":"[DOCS] Update CrowdStrike and SentinelOne connectors","number":219887,"url":"https://github.com/elastic/kibana/pull/219887","mergeCommit":{"message":"[DOCS] Update CrowdStrike and SentinelOne connectors (elastic#219887)","sha":"f3115c6746fe071672911a2e7f74b03bff10b209"}},"sourceBranch":"main","suggestedTargetBranches":["8.19","8.18","9.0"],"targetPullRequestStates":[{"branch":"main","label":"v9.1.0","branchLabelMappingKey":"^v9.1.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/219887","number":219887,"mergeCommit":{"message":"[DOCS] Update CrowdStrike and SentinelOne connectors (elastic#219887)","sha":"f3115c6746fe071672911a2e7f74b03bff10b209"}},{"branch":"8.19","label":"v8.19.0","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"8.18","label":"v8.18.2","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"9.0","label":"v9.0.2","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"}]}] BACKPORT--> Co-authored-by: Lisa Cawley <[email protected]>
1 parent ef4d783 commit dcecfb5

File tree

11 files changed

+133
-11
lines changed

11 files changed

+133
-11
lines changed

docs/reference/connectors-kibana/crowdstrike-action-type.md

Lines changed: 13 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,6 @@ applies_to:
1111

1212
# CrowdStrike connector [crowdstrike-action-type]
1313

14-
::::{warning}
15-
This functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features.
16-
::::
17-
1814
The CrowdStrike connector communicates with CrowdStrike Management Console via REST API.
1915

2016
To use this connector, you must have authority to run {{endpoint-sec}} connectors, which is an **{{connectors-feature}}** sub-feature privilege. Refer to [{{kib}} privileges](docs-content://deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md).
@@ -41,6 +37,17 @@ CrowdStrike client ID
4137
Client secret
4238
: The CrowdStrike API client secret to authenticate the client ID.
4339

44-
## Test connectors [crowdstrike-action-parameters]
40+
## Test connectors [crowdstrike-action-configuration]
41+
42+
You can test connectors as you’re creating or editing the connector in {{kib}}. For example:
43+
44+
:::{image} ../images/crowdstrike-connector-test.png
45+
:screenshot:
46+
:alt: CrowdStrike connector test
47+
:::
48+
49+
The CrowdStrike action has the following configuration properties:
50+
51+
Agent IDs
52+
: Get details about one or more CrowdStrike agent IDs.
4553

46-
At this time, you cannot test the CrowdStrike connector.

docs/reference/connectors-kibana/sentinelone-action-type.md

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,6 @@ applies_to:
1111

1212
# SentinelOne connector [sentinelone-action-type]
1313

14-
::::{warning}
15-
This functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features.
16-
::::
17-
1814
The SentinelOne connector communicates with SentinelOne Management Console via REST API.
1915

2016
To use this connector, you must have authority to run {{endpoint-sec}} connectors, which is an **{{connectors-feature}}** sub-feature privilege. Refer to [{{kib}} privileges](docs-content://deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md).
@@ -40,4 +36,11 @@ URL
4036

4137
## Test connectors [sentinelone-action-parameters]
4238

43-
At this time, you cannot test the SentinelOne connector.
39+
You can test connectors as you're creating or editing the connector in {{kib}}.
40+
For example:
41+
42+
:::{image} ../images/sentinelone-connector-test.png
43+
:alt: SentinelOne connector test
44+
:screenshot:
45+
:::
46+
84.2 KB
Loading
-44.5 KB
Loading
76.4 KB
Loading
-26.6 KB
Loading

oas_docs/output/kibana.serverless.yaml

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -647,6 +647,8 @@ paths:
647647
- $ref: '#/components/schemas/run_closeincident'
648648
- $ref: '#/components/schemas/run_createalert'
649649
- $ref: '#/components/schemas/run_fieldsbyissuetype'
650+
- $ref: '#/components/schemas/run_getagentdetails'
651+
- $ref: '#/components/schemas/run_getagents'
650652
- $ref: '#/components/schemas/run_getchoices'
651653
- $ref: '#/components/schemas/run_getfields'
652654
- $ref: '#/components/schemas/run_getincident'
@@ -64581,6 +64583,42 @@ components:
6458164583
type: string
6458264584
description: The Jira issue type identifier.
6458364585
example: 10024
64586+
run_getagentdetails:
64587+
title: The getAgentDetails subaction
64588+
type: object
64589+
required:
64590+
- subAction
64591+
- subActionParams
64592+
description: The `getAgentDetails` subaction for CrowdStrike connectors.
64593+
properties:
64594+
subAction:
64595+
type: string
64596+
description: The action to test.
64597+
enum:
64598+
- getAgentDetails
64599+
subActionParams:
64600+
type: object
64601+
description: The set of configuration properties for the action.
64602+
required:
64603+
- ids
64604+
properties:
64605+
ids:
64606+
type: array
64607+
description: An array of CrowdStrike agent identifiers.
64608+
items:
64609+
type: string
64610+
run_getagents:
64611+
title: The getAgents subaction
64612+
type: object
64613+
required:
64614+
- subAction
64615+
description: The `getAgents` subaction for SentinelOne connectors.
64616+
properties:
64617+
subAction:
64618+
type: string
64619+
description: The action to test.
64620+
enum:
64621+
- getAgents
6458464622
run_getchoices:
6458564623
title: The getChoices subaction
6458664624
type: object

oas_docs/output/kibana.yaml

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -693,6 +693,8 @@ paths:
693693
- $ref: '#/components/schemas/run_closeincident'
694694
- $ref: '#/components/schemas/run_createalert'
695695
- $ref: '#/components/schemas/run_fieldsbyissuetype'
696+
- $ref: '#/components/schemas/run_getagentdetails'
697+
- $ref: '#/components/schemas/run_getagents'
696698
- $ref: '#/components/schemas/run_getchoices'
697699
- $ref: '#/components/schemas/run_getfields'
698700
- $ref: '#/components/schemas/run_getincident'
@@ -71053,6 +71055,42 @@ components:
7105371055
type: string
7105471056
description: The Jira issue type identifier.
7105571057
example: 10024
71058+
run_getagentdetails:
71059+
title: The getAgentDetails subaction
71060+
type: object
71061+
required:
71062+
- subAction
71063+
- subActionParams
71064+
description: The `getAgentDetails` subaction for CrowdStrike connectors.
71065+
properties:
71066+
subAction:
71067+
type: string
71068+
description: The action to test.
71069+
enum:
71070+
- getAgentDetails
71071+
subActionParams:
71072+
type: object
71073+
description: The set of configuration properties for the action.
71074+
required:
71075+
- ids
71076+
properties:
71077+
ids:
71078+
type: array
71079+
description: An array of CrowdStrike agent identifiers.
71080+
items:
71081+
type: string
71082+
run_getagents:
71083+
title: The getAgents subaction
71084+
type: object
71085+
required:
71086+
- subAction
71087+
description: The `getAgents` subaction for SentinelOne connectors.
71088+
properties:
71089+
subAction:
71090+
type: string
71091+
description: The action to test.
71092+
enum:
71093+
- getAgents
7105671094
run_getchoices:
7105771095
title: The getChoices subaction
7105871096
type: object

oas_docs/overlays/connectors.overlays.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -392,6 +392,8 @@ actions:
392392
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_closeincident.yaml'
393393
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_createalert.yaml'
394394
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_fieldsbyissuetype.yaml'
395+
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_getagentdetails.yaml'
396+
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_getagents.yaml'
395397
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_getchoices.yaml'
396398
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_getfields.yaml'
397399
- $ref: '../../x-pack/platform/plugins/shared/actions/docs/openapi/components/schemas/run_getincident.yaml'
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
title: The getAgentDetails subaction
2+
type: object
3+
required:
4+
- subAction
5+
- subActionParams
6+
description: The `getAgentDetails` subaction for CrowdStrike connectors.
7+
properties:
8+
subAction:
9+
type: string
10+
description: The action to test.
11+
enum:
12+
- getAgentDetails
13+
subActionParams:
14+
type: object
15+
description: The set of configuration properties for the action.
16+
required:
17+
- ids
18+
properties:
19+
ids:
20+
type: array
21+
description: An array of CrowdStrike agent identifiers.
22+
items:
23+
type: string

0 commit comments

Comments
 (0)