-
Notifications
You must be signed in to change notification settings - Fork 1.5k
[AI-5096] DDS: Microsoft Sysmon Agent Integration v1.0.0 #19874
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
[AI-5096] DDS: Microsoft Sysmon Agent Integration v1.0.0 #19874
Conversation
Hi @mauneelsorathia-crest, could you confirm that this PR is not ready for review? I saw it in the "reviewable" column in our JIRA, so checking if it ended up there by error! |
Hi @nubtron, I apologize for any inconvenience, yes the PR is not ready for review yet. I'll mark it open once it is ready. |
Co-authored-by: Michael Cretzman <[email protected]>
Review from Kyle-Neale is dismissed.
Related teams and files:
- agent-integrations
- microsoft_sysmon/README.md
Co-authored-by: Michael Cretzman <[email protected]>
Co-authored-by: Michael Cretzman <[email protected]>
Co-authored-by: Michael Cretzman <[email protected]>
Review from michaelcretzman is dismissed. Related teams and files:
- documentation
- microsoft_sysmon/assets/dashboards/microsoft_sysmon_overview.json
What does this PR do?
Additional notes
This integration does not have any code. It collects logs using the agent host log collection method with log type:
windows_event
.The assets are available in our sandbox and can be shared separately with the required teams.
Review checklist (to be filled by reviewers)
qa/skip-qa
label if the PR doesn't need to be tested during QA.backport/<branch-name>
label to the PR and it will automatically open a backport PR once this one is merged