Skip to content

[mimecast] add geo.ip support for siem logs, keep email.drection lowc…#3116

Merged
andrewkroh merged 4 commits intoelastic:mainfrom
djordje-adzemovic-devtech:fix-and-improve
Apr 25, 2022
Merged

[mimecast] add geo.ip support for siem logs, keep email.drection lowc…#3116
andrewkroh merged 4 commits intoelastic:mainfrom
djordje-adzemovic-devtech:fix-and-improve

Conversation

@djordje-adzemovic-devtech
Copy link
Contributor

…ase and use email.to.adress insread email.user for ttp-url logs

What does this PR do?

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

…ase and use email.to.adress insread email.user for ttp-url logs
@elasticmachine
Copy link

elasticmachine commented Apr 18, 2022

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2022-04-21T08:30:33.378+0000

  • Duration: 20 min 39 sec

Test stats 🧪

Test Results
Failed 0
Passed 61
Skipped 0
Total 61

🤖 GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@andrewkroh
Copy link
Member

/test

@andrewkroh andrewkroh added enhancement New feature or request Team:Security-External Integrations Integration:mimecast Mimecast (Partner supported) labels Apr 18, 2022
@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

Copy link
Contributor

@efd6 efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs elastic-package build.

@efd6
Copy link
Contributor

efd6 commented Apr 19, 2022

/test

Copy link
Contributor

@efd6 efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason not to keep the user name/domain in TTP as well as adding the email.to.address?

@djordje-adzemovic-devtech
Copy link
Contributor Author

@efd6 That is request from Mimecast. They said to change that because in the ttp-ap for searching malicious logs they use email.to.address and email.from.address so they request change in order to keep searching consistent. And they also said to remove user.domain and user.name and accidentally removed user.email also so now I put that back.

@efd6
Copy link
Contributor

efd6 commented Apr 21, 2022

Thanks for the explanation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:mimecast Mimecast (Partner supported)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants