{
  "name": "airlock_digital",
  "title": "Airlock Digital",
  "version": "0.6.0",
  "release": "beta",
  "description": "Collect logs from Airlock Digital with Elastic Agent.",
  "type": "integration",
  "download": "/epr/airlock_digital/airlock_digital-0.6.0.zip",
  "path": "/package/airlock_digital/0.6.0",
  "icons": [
    {
      "src": "/img/airlock_digital-logo.svg",
      "path": "/package/airlock_digital/0.6.0/img/airlock_digital-logo.svg",
      "title": "Airlock Digital",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.0 || ^9.1.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security"
  ],
  "signature_path": "/epr/airlock_digital/airlock_digital-0.6.0.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/airlock_digital/0.6.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/agent-dashboard.png",
      "path": "/package/airlock_digital/0.6.0/img/agent-dashboard.png",
      "title": "Agent Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/execution-histories-dashboard.png",
      "path": "/package/airlock_digital/0.6.0/img/execution-histories-dashboard.png",
      "title": "Execution Histories Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/server-activities-dashboard.png",
      "path": "/package/airlock_digital/0.6.0/img/server-activities-dashboard.png",
      "title": "Server Activities Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/airlock_digital/0.6.0/LICENSE.txt",
    "/package/airlock_digital/0.6.0/changelog.yml",
    "/package/airlock_digital/0.6.0/manifest.yml",
    "/package/airlock_digital/0.6.0/validation.yml",
    "/package/airlock_digital/0.6.0/docs/README.md",
    "/package/airlock_digital/0.6.0/img/agent-dashboard.png",
    "/package/airlock_digital/0.6.0/img/airlock_digital-logo.svg",
    "/package/airlock_digital/0.6.0/img/execution-histories-dashboard.png",
    "/package/airlock_digital/0.6.0/img/server-activities-dashboard.png",
    "/package/airlock_digital/0.6.0/data_stream/agent/manifest.yml",
    "/package/airlock_digital/0.6.0/data_stream/agent/sample_event.json",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/manifest.yml",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/sample_event.json",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/manifest.yml",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/sample_event.json",
    "/package/airlock_digital/0.6.0/kibana/dashboard/airlock_digital-872daa4d-55e1-456e-8998-702849cb10ae.json",
    "/package/airlock_digital/0.6.0/kibana/dashboard/airlock_digital-8a46108a-9cc8-437f-89ae-d862fbc21a7f.json",
    "/package/airlock_digital/0.6.0/kibana/dashboard/airlock_digital-a3bb220e-d9e7-4f7f-92f5-7eb58ecfb38a.json",
    "/package/airlock_digital/0.6.0/kibana/search/airlock_digital-391f6077-2f1f-49ba-810f-7d1a5e8c7c79.json",
    "/package/airlock_digital/0.6.0/kibana/search/airlock_digital-434b0113-b89b-4aad-b78e-0552a36fb44e.json",
    "/package/airlock_digital/0.6.0/kibana/search/airlock_digital-eadcf276-5b6a-4044-9f75-4fdb4263964c.json",
    "/package/airlock_digital/0.6.0/kibana/search/airlock_digital-eb90a63a-e07a-4bf3-8252-39dd90881137.json",
    "/package/airlock_digital/0.6.0/data_stream/agent/fields/base-fields.yml",
    "/package/airlock_digital/0.6.0/data_stream/agent/fields/beats.yml",
    "/package/airlock_digital/0.6.0/data_stream/agent/fields/fields.yml",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/fields/base-fields.yml",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/fields/beats.yml",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/fields/ecs.yml",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/fields/fields.yml",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/fields/base-fields.yml",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/fields/beats.yml",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/fields/ecs.yml",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/fields/fields.yml",
    "/package/airlock_digital/0.6.0/data_stream/agent/agent/stream/cel.yml.hbs",
    "/package/airlock_digital/0.6.0/data_stream/agent/elasticsearch/ingest_pipeline/default.yml",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/agent/stream/cel.yml.hbs",
    "/package/airlock_digital/0.6.0/data_stream/execution_histories/elasticsearch/ingest_pipeline/default.yml",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/agent/stream/cel.yml.hbs",
    "/package/airlock_digital/0.6.0/data_stream/server_activities/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "airlock_digital",
      "title": "Airlock Digital Logs",
      "description": "Collect logs from Airlock Digital API.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the Airlock Digital API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "API Key",
              "description": "API key to authenticate with Airlock Digital API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect logs from Airlock Digital API",
          "description": "Collecting logs via Airlock Digital API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "airlock_digital.agent",
      "title": "Collect Agent logs from Airlock Digital.",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Airlock Digital API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "airlock_digital-agent"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve airlock_digital.agent fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Airlock Digital Agent",
          "description": "Collect Airlock Digital Agent logs.",
          "enabled": false,
          "ingestion_method": "API"
        }
      ],
      "package": "airlock_digital",
      "path": "agent"
    },
    {
      "type": "logs",
      "dataset": "airlock_digital.execution_histories",
      "title": "Collect Execution Histories logs from Airlock Digital.",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Airlock Digital API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "airlock_digital-execution_histories"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve airlock_digital.* fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Airlock Digital Execution Histories",
          "description": "Collect Airlock Digital Execution Histories logs.",
          "enabled": false,
          "ingestion_method": "API"
        }
      ],
      "package": "airlock_digital",
      "path": "execution_histories"
    },
    {
      "type": "logs",
      "dataset": "airlock_digital.server_activities",
      "title": "Collect Server Activities logs from Airlock Digital.",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Airlock Digital API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "airlock_digital-server_activities"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve airlock_digital.* fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Airlock Digital Server Activities",
          "description": "Collect Airlock Digital Server Activities logs.",
          "enabled": false,
          "ingestion_method": "API"
        }
      ],
      "package": "airlock_digital",
      "path": "server_activities"
    }
  ]
}
