Skip to content

[windows] Add Windows AppLocker Data Stream (Packaged app-Execution)#7446

Merged
efd6 merged 8 commits intoelastic:mainfrom
nicpenning:applocker-packaged-app-execution
Aug 20, 2023
Merged

[windows] Add Windows AppLocker Data Stream (Packaged app-Execution)#7446
efd6 merged 8 commits intoelastic:mainfrom
nicpenning:applocker-packaged-app-execution

Conversation

@nicpenning
Copy link
Copy Markdown
Contributor

  • Enhancement

What does this PR do?

This PR adds the Windows AppLocker Packaged app-Execution data stream which allows the ingestion of those events from the Windows Event Log. This is the final AppLocker data stream to get added.

Resolves Part of - #6979

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

@nicpenning nicpenning requested review from a team as code owners August 17, 2023 14:45
@elasticmachine
Copy link
Copy Markdown

elasticmachine commented Aug 17, 2023

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-08-20T23:23:16.570+0000

  • Duration: 19 min 45 sec

Test stats 🧪

Test Results
Failed 0
Passed 150
Skipped 0
Total 150

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@nicpenning
Copy link
Copy Markdown
Contributor Author

Ready for review and testing!

@nicpenning
Copy link
Copy Markdown
Contributor Author

Now ready to go. Had to update README.md with the new data stream.

@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@efd6
Copy link
Copy Markdown
Contributor

efd6 commented Aug 20, 2023

/test

@nicpenning
Copy link
Copy Markdown
Contributor Author

Missing the HTTP JSON config updates. I will get that updated soon. Sorry about that.

@efd6
Copy link
Copy Markdown
Contributor

efd6 commented Aug 20, 2023

/test

@elasticmachine
Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (8/8) 💚
Files 91.667% (11/12) 👎 -4.963
Classes 91.667% (11/12) 👎 -4.963
Methods 85.156% (109/128) 👎 -6.808
Lines 92.462% (5728/6195) 👍 4.131
Conditionals 100.0% (0/0) 💚

@efd6 efd6 merged commit 3e323a6 into elastic:main Aug 20, 2023
@nicpenning nicpenning deleted the applocker-packaged-app-execution branch August 21, 2023 00:06
@elasticmachine
Copy link
Copy Markdown

Package windows - 1.32.0 containing this change is available at https://epr.elastic.co/search?package=windows

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:windows Windows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants