{
  "name": "1password",
  "title": "1Password",
  "version": "1.39.2",
  "release": "ga",
  "description": "Collect logs from 1Password with Elastic Agent.",
  "type": "integration",
  "download": "/epr/1password/1password-1.39.2.zip",
  "path": "/package/1password/1.39.2",
  "icons": [
    {
      "src": "/img/1password-logo-light-bg.svg",
      "path": "/package/1password/1.39.2/img/1password-logo-light-bg.svg",
      "title": "1Password",
      "size": "116x116",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.4 || ^9.0.7"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "credential_management"
  ],
  "signature_path": "/epr/1password/1password-1.39.2.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/1password/1.39.2/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/1password-signinattempts-screenshot.png",
      "path": "/package/1password/1.39.2/img/1password-signinattempts-screenshot.png",
      "title": "Sign-in attempts",
      "size": "1918x963",
      "type": "image/png"
    },
    {
      "src": "/img/1password-itemusages-screenshot.png",
      "path": "/package/1password/1.39.2/img/1password-itemusages-screenshot.png",
      "title": "Item usages",
      "size": "1916x965",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/1password/1.39.2/LICENSE.txt",
    "/package/1password/1.39.2/changelog.yml",
    "/package/1password/1.39.2/manifest.yml",
    "/package/1password/1.39.2/validation.yml",
    "/package/1password/1.39.2/docs/README.md",
    "/package/1password/1.39.2/img/1password-itemusages-screenshot.png",
    "/package/1password/1.39.2/img/1password-logo-light-bg.svg",
    "/package/1password/1.39.2/img/1password-signinattempts-screenshot.png",
    "/package/1password/1.39.2/kibana/tags.yml",
    "/package/1password/1.39.2/data_stream/audit_events/manifest.yml",
    "/package/1password/1.39.2/data_stream/audit_events/sample_event.json",
    "/package/1password/1.39.2/data_stream/item_usages/manifest.yml",
    "/package/1password/1.39.2/data_stream/item_usages/sample_event.json",
    "/package/1password/1.39.2/data_stream/signin_attempts/manifest.yml",
    "/package/1password/1.39.2/data_stream/signin_attempts/sample_event.json",
    "/package/1password/1.39.2/kibana/dashboard/1password-audit-events-full-dashboard.json",
    "/package/1password/1.39.2/kibana/dashboard/1password-item-usages-full-dashboard.json",
    "/package/1password/1.39.2/kibana/dashboard/1password-signin-attempts-full-dashboard.json",
    "/package/1password/1.39.2/kibana/search/1password-all-events.json",
    "/package/1password/1.39.2/kibana/search/1password-audit-events.json",
    "/package/1password/1.39.2/kibana/search/1password-item-usages.json",
    "/package/1password/1.39.2/kibana/search/1password-signin-attempts.json",
    "/package/1password/1.39.2/data_stream/audit_events/fields/base-fields.yml",
    "/package/1password/1.39.2/data_stream/audit_events/fields/fields.yml",
    "/package/1password/1.39.2/data_stream/item_usages/fields/base-fields.yml",
    "/package/1password/1.39.2/data_stream/item_usages/fields/fields.yml",
    "/package/1password/1.39.2/data_stream/signin_attempts/fields/base-fields.yml",
    "/package/1password/1.39.2/data_stream/signin_attempts/fields/fields.yml",
    "/package/1password/1.39.2/data_stream/audit_events/agent/stream/httpjson.yml.hbs",
    "/package/1password/1.39.2/data_stream/audit_events/elasticsearch/ingest_pipeline/default.yml",
    "/package/1password/1.39.2/data_stream/item_usages/agent/stream/httpjson.yml.hbs",
    "/package/1password/1.39.2/data_stream/item_usages/elasticsearch/ingest_pipeline/default.yml",
    "/package/1password/1.39.2/data_stream/signin_attempts/agent/stream/httpjson.yml.hbs",
    "/package/1password/1.39.2/data_stream/signin_attempts/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "1password",
      "title": "1Password Events",
      "description": "Collect events from 1Password Events Reporting",
      "inputs": [
        {
          "type": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL of 1Password Events API Server",
              "description": "options: https://events.1password.com, https://events.1password.ca, https://events.1password.eu, https://events.ent.1password.com. path is automatic\n",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://events.1password.com"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "token",
              "type": "password",
              "title": "1Password Authorization Token",
              "description": "Bearer Token, e.g. \"eyJhbGciO...\"\n",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "disable_keep_alive",
              "type": "bool",
              "title": "Disable HTTP Keep-Alives",
              "description": "Controls whether HTTP keep-alives are disabled.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            }
          ],
          "title": "Collect events from 1Password Events API",
          "description": "Collect sign-in attempt, item usages, and audit events from 1Password via the 1Password Events API"
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "beta"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "1password.audit_events",
      "title": "Collect 1Password audit events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "Number of events to fetch on each request",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval to query 1Password Events API",
              "description": "Go Duration syntax (eg. 10s)",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "10s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "1password-audit_events"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Collect 1Password audit events",
          "description": "Collect audit events from 1Password via the 1Password Events API",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "1password",
      "path": "audit_events"
    },
    {
      "type": "logs",
      "dataset": "1password.item_usages",
      "title": "Collect 1Password item usages events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "Number of events to fetch on each request",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval to query 1Password Events API",
              "description": "Go Duration syntax (eg. 10s)",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "10s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "1password-item_usages"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Collect 1Password item usages events",
          "description": "Collect item usages from 1Password via the 1Password Events API",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "1password",
      "path": "item_usages"
    },
    {
      "type": "logs",
      "dataset": "1password.signin_attempts",
      "title": "1Password sign-in attempt events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "Number of events to fetch on each request",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval to query 1Password Events API",
              "description": "Go Duration syntax (eg. 10s)",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "10s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "1password-signin_attempts"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Collect 1Password sign-in attempt events",
          "description": "Collect sign-in attempts from 1Password via the 1Password Events API",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "1password",
      "path": "signin_attempts"
    }
  ]
}
