{
  "name": "anthropic",
  "title": "Anthropic",
  "version": "1.1.2",
  "release": "ga",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Collect activity logs from Claude's Compliance API.",
  "type": "integration",
  "download": "/epr/anthropic/anthropic-1.1.2.zip",
  "path": "/package/anthropic/1.1.2",
  "icons": [
    {
      "src": "/img/anthropic-logo.svg",
      "path": "/package/anthropic/1.1.2/img/anthropic-logo.svg",
      "title": "Anthropic logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.0 || ^9.1.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/integration-experience"
  },
  "categories": [
    "security",
    "observability"
  ],
  "signature_path": "/epr/anthropic/anthropic-1.1.2.zip.sig",
  "format_version": "3.4.2",
  "readme": "/package/anthropic/1.1.2/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/anthropic-overview1.png",
      "path": "/package/anthropic/1.1.2/img/anthropic-overview1.png",
      "title": "Anthropic Overview Metrics",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/anthropic-overview2.png",
      "path": "/package/anthropic/1.1.2/img/anthropic-overview2.png",
      "title": "Anthropic Overview Events",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/anthropic/1.1.2/LICENSE.txt",
    "/package/anthropic/1.1.2/changelog.yml",
    "/package/anthropic/1.1.2/manifest.yml",
    "/package/anthropic/1.1.2/validation.yml",
    "/package/anthropic/1.1.2/docs/README.md",
    "/package/anthropic/1.1.2/img/anthropic-logo.svg",
    "/package/anthropic/1.1.2/img/anthropic-overview1.png",
    "/package/anthropic/1.1.2/img/anthropic-overview2.png",
    "/package/anthropic/1.1.2/data_stream/audit/manifest.yml",
    "/package/anthropic/1.1.2/data_stream/audit/sample_event.json",
    "/package/anthropic/1.1.2/kibana/dashboard/anthropic-9d6c05e4-fea8-4f57-8b27-1243c99793ab.json",
    "/package/anthropic/1.1.2/kibana/search/anthropic-15990230-2301-4bb9-b00e-622b4d0bbd9a.json",
    "/package/anthropic/1.1.2/data_stream/audit/fields/base-fields.yml",
    "/package/anthropic/1.1.2/data_stream/audit/fields/beats.yml",
    "/package/anthropic/1.1.2/data_stream/audit/fields/ecs.yml",
    "/package/anthropic/1.1.2/data_stream/audit/fields/fields.yml",
    "/package/anthropic/1.1.2/data_stream/audit/agent/stream/cel.yml.hbs",
    "/package/anthropic/1.1.2/data_stream/audit/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/anthropic/1.1.2/data_stream/audit/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "anthropic",
      "title": "Anthropic logs",
      "description": "Collect activity logs from Claude's Compliance API.",
      "inputs": [
        {
          "type": "cel",
          "title": "Collect Anthropic compliance activity logs",
          "description": "Collect activity logs from Claude's Compliance API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "beta"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "anthropic.audit",
      "title": "Compliance activity audit logs",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_key",
              "type": "password",
              "title": "API Key",
              "description": "Compliance Access Key (`sk-ant-api01-...`) or Admin API Key (`sk-ant-admin01-...`) with the `read:compliance_activities` scope. See Anthropic's guide to request access and create keys.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Polling Interval",
              "description": "How frequently to poll for new compliance activities. The default of 5 minutes keeps usage well within the 600 requests per minute per organization rate limit.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Lookback Interval",
              "description": "How far back to collect activities on the first run (for example `24h` or `7d`).",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "activity_types",
              "type": "text",
              "title": "Activity Types",
              "description": "Optional list of activity type values to collect (for example `user_login`, `api_key_created`). Leave empty to collect all activity types.",
              "multi": true,
              "required": false,
              "show_user": true
            },
            {
              "name": "actor_ids",
              "type": "text",
              "title": "Actor IDs",
              "description": "Optional list of actor IDs to filter to (for example `user_01AbCdEfGhIjKlMnOpQrStUv`).",
              "multi": true,
              "required": false,
              "show_user": true
            },
            {
              "name": "organization_ids",
              "type": "text",
              "title": "Organization IDs",
              "description": "Optional list of organization IDs or UUIDs to filter to (for example `org_01AbCdEfGhIjKlMnOpQrStUv`).",
              "multi": true,
              "required": false,
              "show_user": true
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Page Size",
              "description": "Number of activities per API page (1–5000).",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 1000
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original activity JSON in the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "proxy_url",
              "type": "url",
              "title": "Proxy URL",
              "description": "HTTP proxy URL for API requests, for example `http://proxy.example.com:8080`.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "url",
              "type": "url",
              "title": "Anthropic API URL",
              "description": "Base URL for the Anthropic API.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://api.anthropic.com"
            },
            {
              "name": "anthropic_version",
              "type": "text",
              "title": "API Version",
              "description": "Value sent in the `anthropic-version` request header.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "2023-06-01"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Timeout for HTTP requests to the Anthropic Compliance API.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "60s"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [SSL](https://www.elastic.co/docs/reference/elastic-agent/agent-ssl-options) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "anthropic-audit"
              ]
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/docs/reference/integrations/inputs/input-cel#_resource_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Compliance activity audit logs",
          "description": "Collect compliance activity audit events from the Anthropic Compliance API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "anthropic",
      "path": "audit"
    }
  ]
}
