Skip to content

Add Category::SIEM classifier tag to Trellix, Cofense Triage, Anthropic Compliance Logs - #24857

Draft
fabrequentin wants to merge 1 commit into
masterfrom
quentin.fabre/sec-35935-siem-classifier-tags
Draft

Add Category::SIEM classifier tag to Trellix, Cofense Triage, Anthropic Compliance Logs#24857
fabrequentin wants to merge 1 commit into
masterfrom
quentin.fabre/sec-35935-siem-classifier-tags

Conversation

@fabrequentin

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds the Category::SIEM classifier tag to the manifest.json of three integrations: Trellix Endpoint Security (ENS), Cofense Triage, and Claude Compliance (Anthropic Compliance Logs).

Motivation

These integrations are relevant to Cloud SIEM (log collection/security data used in detection content) but were missing the Category::SIEM classifier tag, so they don't surface correctly in SIEM-focused integration listings.

SEC-35935

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add qa/required if this PR needs QA validation, or qa/skip-qa if it does not. Exactly one of the two is required.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

…ic Compliance Logs

These integrations are relevant to Cloud SIEM but are missing the
Category::SIEM classifier tag in their manifest.

SEC-35935
@datadog-official

Copy link
Copy Markdown
Contributor

Pipelines

⚠️ Warnings

🚦 1 Pipeline job failed

Validate repository | Run Validations / Validate   View in Datadog   GitHub Actions

See error Pull request is missing an Agent-release QA decision label.

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 89ee180 | Docs | Datadog PR Page | Give us feedback!

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

evalya-impact-summary

evalya impact analysis
Impact analysis: 0 selected, 0 skipped (of 0 test tasks)
Publish tasks:   1 (always emitted)
Diff (3 files):
  anthropic_compliance_logs/manifest.json
  cofense_triage/manifest.json
  trellix_endpoint_security/manifest.json

Debug a specific task: evalya plan impact --path <path> --task <task>

Learn more about CI impact filtering

@fabrequentin fabrequentin added the qa/skip-qa Automatically skip this PR for the next QA label Aug 13, 2026
@dd-octo-sts

dd-octo-sts Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Validation Report

All 21 validations passed.

Show details
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
qa-label Validate the pull request declares whether it needs QA for the next Agent release
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants