Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions detection_rules/packaging.py
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
from .misc import JS_LICENSE, cached
from .rule import TOMLRule, BaseQueryRuleData, RULES_DIR, ThreatMapping
from .rule import downgrade_contents_from_rule
from .schemas import CurrentSchema
from .schemas import CurrentSchema, definitions
from .utils import Ndjson, get_path, get_etc_path, load_etc_dump, save_etc_dump

RELEASE_DIR = get_path("releases")
Expand Down Expand Up @@ -485,7 +485,7 @@ def _generate_registry_package(self, save_dir):

package_dir = Path(save_dir).joinpath(manifest.version)
docs_dir = package_dir / 'docs'
rules_dir = package_dir / 'kibana' / 'security_rule'
rules_dir = package_dir / 'kibana' / definitions.ASSET_TYPE

docs_dir.mkdir(parents=True)
rules_dir.mkdir(parents=True)
Expand All @@ -498,7 +498,8 @@ def _generate_registry_package(self, save_dir):
# shutil.copyfile(CHANGELOG_FILE, str(rules_dir.joinpath('CHANGELOG.json')))

for rule in self.rules:
rule.save_json(Path(rules_dir.joinpath(f'rule-{rule.id}.json')))
with Path(rules_dir.joinpath(f'rule-{rule.id}.json')).open("w", encoding="utf-8") as f:
json.dump(rule.get_asset(), f, indent=2, sort_keys=True)
Comment thread
rw-access marked this conversation as resolved.

readme_text = ('# Detection rules\n\n'
'The detection rules package stores all the security rules '
Expand Down
4 changes: 4 additions & 0 deletions detection_rules/rule.py
Original file line number Diff line number Diff line change
Expand Up @@ -432,6 +432,10 @@ def id(self):
def name(self):
return self.contents.data.name

def get_asset(self) -> dict:
"""Generate the relevant fleet compatible asset."""
return {"id": self.id, "attributes": self.contents.to_api_format(), "type": definitions.ASSET_TYPE}

def save_toml(self):
converted = self.contents.to_dict()
toml_write(converted, str(self.path.absolute()))
Expand Down
2 changes: 2 additions & 0 deletions detection_rules/schemas/definitions.py
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@
from marshmallow import validate
from marshmallow_dataclass import NewType

ASSET_TYPE = "security_rule"

DATE_PATTERN = r'\d{4}/\d{2}/\d{2}'
MATURITY_LEVELS = ['development', 'experimental', 'beta', 'production', 'deprecated']
OS_OPTIONS = ['windows', 'linux', 'macos']
Expand Down