{
  "name": "beyondinsight_password_safe",
  "title": "BeyondInsight and Password Safe",
  "version": "1.3.2",
  "release": "ga",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Ingest privileged access management (PAM) data from BeyondTrust's BeyondInsight PAM Reporting Platform and Password Safe, using Elastic Agent.",
  "type": "integration",
  "download": "/epr/beyondinsight_password_safe/beyondinsight_password_safe-1.3.2.zip",
  "path": "/package/beyondinsight_password_safe/1.3.2",
  "icons": [
    {
      "src": "/img/logo.svg",
      "path": "/package/beyondinsight_password_safe/1.3.2/img/logo.svg",
      "title": "BeyondTrust logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "credential_management",
    "iam"
  ],
  "signature_path": "/epr/beyondinsight_password_safe/beyondinsight_password_safe-1.3.2.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/beyondinsight_password_safe/1.3.2/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/overview.png",
      "path": "/package/beyondinsight_password_safe/1.3.2/img/overview.png",
      "title": "Overview",
      "size": "3024x1640",
      "type": "image/png"
    },
    {
      "src": "/img/sessionandasset.png",
      "path": "/package/beyondinsight_password_safe/1.3.2/img/sessionandasset.png",
      "title": "Session and Asset",
      "size": "3024x1640",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/beyondinsight_password_safe/1.3.2/LICENSE.txt",
    "/package/beyondinsight_password_safe/1.3.2/changelog.yml",
    "/package/beyondinsight_password_safe/1.3.2/manifest.yml",
    "/package/beyondinsight_password_safe/1.3.2/docs/README.md",
    "/package/beyondinsight_password_safe/1.3.2/img/logo.svg",
    "/package/beyondinsight_password_safe/1.3.2/img/overview.png",
    "/package/beyondinsight_password_safe/1.3.2/img/sessionandasset.png",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/asset/manifest.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/asset/sample_event.json",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedaccount/manifest.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedaccount/sample_event.json",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedsystem/manifest.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedsystem/sample_event.json",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/session/manifest.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/session/sample_event.json",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/useraudit/manifest.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/useraudit/sample_event.json",
    "/package/beyondinsight_password_safe/1.3.2/kibana/dashboard/beyondinsight_password_safe-10ef927f-cc3f-4cc5-a31a-4e197143ee60.json",
    "/package/beyondinsight_password_safe/1.3.2/kibana/dashboard/beyondinsight_password_safe-9a5cd258-b7de-47bf-b17c-a3bd1c563b4c.json",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/asset/fields/base-fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/asset/fields/fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedaccount/fields/base-fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedaccount/fields/fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedsystem/fields/base-fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedsystem/fields/fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/session/fields/base-fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/session/fields/fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/useraudit/fields/base-fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/useraudit/fields/fields.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/asset/agent/stream/cel.yml.hbs",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/asset/elasticsearch/ingest_pipeline/default.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedaccount/agent/stream/cel.yml.hbs",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedaccount/elasticsearch/ingest_pipeline/default.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedsystem/agent/stream/cel.yml.hbs",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/managedsystem/elasticsearch/ingest_pipeline/default.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/session/agent/stream/cel.yml.hbs",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/session/elasticsearch/ingest_pipeline/default.yml",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/useraudit/agent/stream/cel.yml.hbs",
    "/package/beyondinsight_password_safe/1.3.2/data_stream/useraudit/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "beyondinsight",
      "title": "BeyondInsight and Password Safe Events",
      "description": "Collect events from BeyondInsight and Password Safe",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Base URL of BeyondInsight and Password Safe API",
              "description": "For example, `https://the-server/BeyondTrust/api/public/v3` or `https://the-cloud-instance-url/BeyondTrust/api/public/v3`",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "username",
              "type": "text",
              "title": "Username",
              "description": "This is the username you have created in BeyondInsight.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "apikey",
              "type": "text",
              "title": "API key",
              "description": "This is the API key you have created in BeyondInsight.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "password",
              "type": "text",
              "title": "User Password",
              "description": "This is the user password you have created in BeyondInsight.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "Collect events from the BeyondInsight and Password Safe API",
          "description": "Collect sign-in attempts, item usages, and audit events from BeyondInsight and Password Safe via API"
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "beyondinsight_password_safe.asset",
      "title": "BeyondInsight and Password Safe Assets Events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Data for all assets will be refetched at this interval. The supported time units are \"h\", \"m\", \"s\".",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "4h"
            },
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "The number of events to fetch per request.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to be applied to the events.",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "beyondinsight_password_safe.asset"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve Original Event",
              "description": "Preserves a raw copy of the original event in the `event.original` field.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors can be used to reduce the number of fields in the exported event, or to enhance the event with additional metadata. This is executed in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "BeyondInsight Assets",
          "description": "Asset inventory data from workgroups with system details.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "beyondinsight_password_safe",
      "path": "asset"
    },
    {
      "type": "logs",
      "dataset": "beyondinsight_password_safe.managedaccount",
      "title": "BeyondInsight and Password Safe Managed Accounts Events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Data for all managed accounts will be refetched at this interval. The supported time units are \"h\", \"m\", \"s\".",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "4h"
            },
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "The number of events to fetch per request.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to be applied to the events.",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "beyondinsight_password_safe.managedaccount"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve Original Event",
              "description": "Preserves a raw copy of the original event in the `event.original` field.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors can be used to reduce the number of fields in the exported event or to enhance the event with additional metadata. This is executed in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Password Safe Managed Accounts",
          "description": "Managed account info with security policies and permissions.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "beyondinsight_password_safe",
      "path": "managedaccount"
    },
    {
      "type": "logs",
      "dataset": "beyondinsight_password_safe.managedsystem",
      "title": "BeyondInsight and Password Safe Managed Systems Events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Data for all managed systems will be refetched at this interval. The supported time units are \"h\", \"m\", \"s\".",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "4h"
            },
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "The number of events to fetch per request.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to be applied to the events.",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "beyondinsight_password_safe.managedsystem"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve Original Event",
              "description": "Preserves a raw copy of the original event in the `event.original` field.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors can be used to reduce the number of fields in the exported event, or to enhance the event with additional metadata. This is executed in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Password Safe Managed Systems",
          "description": "Systems managed by Password Safe with configurations.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "beyondinsight_password_safe",
      "path": "managedsystem"
    },
    {
      "type": "logs",
      "dataset": "beyondinsight_password_safe.session",
      "title": "BeyondInsight and Password Safe Session Events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Data for all sessions will be refetched at this interval. The supported time units are \"h\", \"m\", \"s\".",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "5m"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to be applied to the events.",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "beyondinsight_password_safe.session"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve Original Event",
              "description": "Preserves a raw copy of the original event in the `event.original` field.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors can be used to reduce the number of fields in the exported event or to enhance the event with additional metadata. This is executed in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Password Safe Sessions",
          "description": "Session monitoring data with status and duration metrics.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "beyondinsight_password_safe",
      "path": "session"
    },
    {
      "type": "logs",
      "dataset": "beyondinsight_password_safe.useraudit",
      "title": "BeyondInsight and Password Safe User Audit Events",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which new audit events will be fetched. The supported time units are \"h\", \"m\", \"s\".",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to collect BeyondInsight user audit events from the API. The supported time units are \"h\", \"m\", \"s\".",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "2160h"
            },
            {
              "name": "limit",
              "type": "integer",
              "title": "Limit",
              "description": "The number of events to fetch per request.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to be applied to the events.",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "beyondinsight_password_safe.useraudit"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve Original Event",
              "description": "Preserves a raw copy of the original event in the `event.original` field.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors can be used to reduce the number of fields in the exported event, or to enhance the event with additional metadata. This is executed in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "BeyondInsight User Audit Events",
          "description": "User audit activity tracking with authentication events.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "beyondinsight_password_safe",
      "path": "useraudit"
    }
  ]
}
