-
Notifications
You must be signed in to change notification settings - Fork 474
Adding agent exclusion filters to dga, lmd and problemchild packages #13058
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@mgarzon The filters for DGA and problemchild look good. You'll need to add filter to the LMD jobs that aren't RDP based. Also, please bump the versions of manifest.yml
and changelog.yml
as well as transform.yml
where necessary.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for addressing comments from Kirti; this looks good to me
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changes look good to me! Did you try testing the packages locally? If so, could you please add screenshots?
Pinging @elastic/sec-applied-ml (Team:Security-Applied ML) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Fixed indentation problem.
|
💚 Build Succeeded
History
|
Package dga - 2.3.0 containing this change is available at https://epr.elastic.co/package/dga/2.3.0/ |
Package lmd - 2.4.0 containing this change is available at https://epr.elastic.co/package/lmd/2.4.0/ |
Package problemchild - 2.4.0 containing this change is available at https://epr.elastic.co/package/problemchild/2.4.0/ |
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
As described in https://github.com/elastic/security-team/issues/11532, we have added filters to exclude any processing related to the elastic endpoint agents.