Skip to content

[AI-5096] DDS: Microsoft Sysmon Agent Integration v1.0.0 #19874

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 21 commits into
base: master
Choose a base branch
from

Conversation

mauneelsorathia-crest
Copy link
Contributor

@mauneelsorathia-crest mauneelsorathia-crest commented Mar 19, 2025

What does this PR do?

  • This is an initial release PR of Microsoft Sysmon integration including all the required assets. This is agent based integration.

Additional notes

This integration does not have any code. It collects logs using the agent host log collection method with log type: windows_event.
The assets are available in our sandbox and can be shared separately with the required teams.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@mauneelsorathia-crest mauneelsorathia-crest changed the title DDS: Microsoft Sysmon Agent Integration v1.0.0 [AI-5096] DDS: Microsoft Sysmon Agent Integration v1.0.0 Mar 21, 2025
@nubtron
Copy link
Contributor

nubtron commented Mar 24, 2025

Hi @mauneelsorathia-crest, could you confirm that this PR is not ready for review? I saw it in the "reviewable" column in our JIRA, so checking if it ended up there by error!

@mauneelsorathia-crest
Copy link
Contributor Author

mauneelsorathia-crest commented Mar 25, 2025

Hi @mauneelsorathia-crest, could you confirm that this PR is not ready for review? I saw it in the "reviewable" column in our JIRA, so checking if it ended up there by error!

Hi @nubtron, I apologize for any inconvenience, yes the PR is not ready for review yet. I'll mark it open once it is ready.

@mauneelsorathia-crest mauneelsorathia-crest changed the title [AI-5096] DDS: Microsoft Sysmon Agent Integration v1.0.0 DDS: Microsoft Sysmon Agent Integration v1.0.0 Mar 25, 2025
Kyle-Neale
Kyle-Neale previously approved these changes Mar 31, 2025
Co-authored-by: Michael Cretzman <[email protected]>
@temporal-github-worker-1 temporal-github-worker-1 bot dismissed Kyle-Neale’s stale review April 1, 2025 06:36

Review from Kyle-Neale is dismissed.
Related teams and files:

  • agent-integrations
    • microsoft_sysmon/README.md
michaelcretzman
michaelcretzman previously approved these changes Apr 2, 2025
@temporal-github-worker-1 temporal-github-worker-1 bot dismissed michaelcretzman’s stale review April 8, 2025 09:47

Review from michaelcretzman is dismissed. Related teams and files:

  • documentation
    • microsoft_sysmon/assets/dashboards/microsoft_sysmon_overview.json
@ieguinoa ieguinoa added the assets/deploy-logs-staging ONLY USED BY Logs Backend - Validates that a PR is OK to go to staging label Apr 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants