{
  "name": "gigamon",
  "title": "Gigamon",
  "version": "2.4.0",
  "release": "ga",
  "description": "Collect logs from Gigamon with Elastic Agent.",
  "type": "integration",
  "download": "/epr/gigamon/gigamon-2.4.0.zip",
  "path": "/package/gigamon/2.4.0",
  "icons": [
    {
      "src": "/img/gigamon-logo.svg",
      "path": "/package/gigamon/2.4.0/img/gigamon-logo.svg",
      "title": "Gigamon logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.13.0 || ^9.0.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "partner",
    "github": "elastic/integration-experience"
  },
  "categories": [
    "custom",
    "security",
    "network",
    "application_observability",
    "observability"
  ],
  "signature_path": "/epr/gigamon/gigamon-2.4.0.zip.sig",
  "format_version": "3.1.3",
  "readme": "/package/gigamon/2.4.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/App_Insights_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/App_Insights_Dashboard.png",
      "title": "Gigamon App Insight Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/Identifier_Analysis_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Identifier_Analysis_Dashboard.png",
      "title": "Gigamon Identifier Analysis Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/M21-31_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/M21-31_Dashboard.png",
      "title": "Gigamon M21-31 Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/PCI_Compliance_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/PCI_Compliance_Dashboard.png",
      "title": "Gigamon PCI Compliance Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/Rogue_Activity_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Rogue_Activity_Dashboard.png",
      "title": "Gigamon Rogue Activity Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/Security_Posture_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Security_Posture_Dashboard.png",
      "title": "Gigamon Security Posture Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/Troubleshooting_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Troubleshooting_Dashboard.png",
      "title": "Gigamon Troubleshooting Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/Suspicious_Activity_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Suspicious_Activity_Dashboard.png",
      "title": "Gigamon Suspicious Activity Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/API_Inventory_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/API_Inventory_Dashboard.png",
      "title": "Gigamon API Inventory Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/API_Vulnerabilities_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/API_Vulnerabilities_Dashboard.png",
      "title": "Gigamon API Vulnerabilities Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/Network_Telemetry_Insights_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Network_Telemetry_Insights_Dashboard.png",
      "title": "Gigamon Network Telemetry Insights  Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/Visibility_and_Analytics_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Visibility_and_Analytics_Dashboard.png",
      "title": "Gigamon ZeroTrust  Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/Network_and_Environment_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Network_and_Environment_Dashboard.png",
      "title": "Gigamon ZeroTrust  Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/Device_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Device_Dashboard.png",
      "title": "Gigamon ZeroTrust  Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/Operational_Technology_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/Operational_Technology_Dashboard.png",
      "title": "Gigamon Operational Technology Dashboard Screenshot",
      "size": "600x600"
    },
    {
      "src": "/img/AI_Insights_Dashboard.png",
      "path": "/package/gigamon/2.4.0/img/AI_Insights_Dashboard.png",
      "title": "Gigamon AI Insights Dashboard Screenshot",
      "size": "600x600"
    }
  ],
  "assets": [
    "/package/gigamon/2.4.0/LICENSE.txt",
    "/package/gigamon/2.4.0/changelog.yml",
    "/package/gigamon/2.4.0/manifest.yml",
    "/package/gigamon/2.4.0/validation.yml",
    "/package/gigamon/2.4.0/docs/README.md",
    "/package/gigamon/2.4.0/img/AI_Insights_Dashboard.png",
    "/package/gigamon/2.4.0/img/API_Inventory_Dashboard.png",
    "/package/gigamon/2.4.0/img/API_Vulnerabilities_Dashboard.png",
    "/package/gigamon/2.4.0/img/App_Insights_Dashboard.png",
    "/package/gigamon/2.4.0/img/Device_Dashboard.png",
    "/package/gigamon/2.4.0/img/Identifier_Analysis_Dashboard.png",
    "/package/gigamon/2.4.0/img/M21-31_Dashboard.png",
    "/package/gigamon/2.4.0/img/Network_Telemetry_Insights_Dashboard.png",
    "/package/gigamon/2.4.0/img/Network_and_Environment_Dashboard.png",
    "/package/gigamon/2.4.0/img/Operational_Technology_Dashboard.png",
    "/package/gigamon/2.4.0/img/PCI_Compliance_Dashboard.png",
    "/package/gigamon/2.4.0/img/Rogue_Activity_Dashboard.png",
    "/package/gigamon/2.4.0/img/Security_Posture_Dashboard.png",
    "/package/gigamon/2.4.0/img/Suspicious_Activity_Dashboard.png",
    "/package/gigamon/2.4.0/img/Troubleshooting_Dashboard.png",
    "/package/gigamon/2.4.0/img/Visibility_and_Analytics_Dashboard.png",
    "/package/gigamon/2.4.0/img/ZeroTrust_Dashboard.png",
    "/package/gigamon/2.4.0/img/gigamon-logo.svg",
    "/package/gigamon/2.4.0/data_stream/ami/manifest.yml",
    "/package/gigamon/2.4.0/data_stream/ami/sample_event.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-032aab7b-87b2-444c-8c86-956d092598fb.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-20c6c22a-dae0-4a0a-ad8c-043f878fc109.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-3523b534-7525-44a7-808f-6a9f3235a67d.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-3e5652b3-1b0e-428f-9dc3-78d179ce2463.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-46931a21-a33e-43af-aadf-da8d6446b9cc.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-4ae2cd9a-3eef-42c6-a02c-731ce74d94ac.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-60d20029-8831-4156-bee7-fbcf2213486d.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-62291e9e-8b75-4f23-9121-79959da99b3b.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-64ca15b3-8327-4940-8b35-0e75ab3a73c6.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-80233efd-b0b8-455d-8b9c-8483d7f898d4.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-855a64dc-1a72-403f-932b-a5b848378f7e.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-87c75cf5-252c-42c3-a327-3d0539c10845.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-8bcbcb16-2e63-4923-b916-904a6d6f0ed8.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-8d02ca6f-9333-4cab-8b8a-a141e9fccdcf.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-8f772203-64e0-4d1b-bb0e-14fa57b4b754.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-c1be36a7-86aa-4442-b07f-facd9db043f3.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-d6cecabb-f026-4823-914d-b4d61fd61787.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-d866be49-47b2-4306-a2be-d5cb6b6ab9c8.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-e192a946-8287-450a-a8f0-e23de9f95dae.json",
    "/package/gigamon/2.4.0/kibana/dashboard/gigamon-e733c64e-6ea9-4dd6-a8ca-3914274598f3.json",
    "/package/gigamon/2.4.0/data_stream/ami/fields/base-fields.yml",
    "/package/gigamon/2.4.0/data_stream/ami/fields/beats.yml",
    "/package/gigamon/2.4.0/data_stream/ami/fields/fields.yml",
    "/package/gigamon/2.4.0/data_stream/ami/fields/ml-dga.yml",
    "/package/gigamon/2.4.0/data_stream/ami/agent/stream/http_endpoint.yml.hbs",
    "/package/gigamon/2.4.0/data_stream/ami/agent/stream/udp.yml.hbs",
    "/package/gigamon/2.4.0/data_stream/ami/elasticsearch/ingest_pipeline/cef-pipeline.yml",
    "/package/gigamon/2.4.0/data_stream/ami/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "gigamon",
      "title": "Gigamon AMI",
      "description": "Collect logs from Gigamon AMI via HTTP Endpoint (JSON) or UDP (CEF)",
      "inputs": [
        {
          "type": "http_endpoint",
          "vars": [
            {
              "name": "listen_address",
              "type": "text",
              "title": "Listen Address",
              "description": "The bind address to listen for http endpoint connections. Set to '0.0.0.0' to bind to all available interfaces.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "Collect json data from Gigamon AMI via HTTP Endpoint",
          "description": "Collect json data from Gigamon AMI via HTTP Endpoint"
        },
        {
          "type": "udp",
          "title": "Collect CEF logs from Gigamon AMI (input: udp)",
          "description": "Collect CEF logs from Gigamon AMI (input: udp)"
        }
      ],
      "multiple": true
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "gigamon.ami",
      "title": "Gigamon Application Metadata Intelligence (AMI) Logs",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "http_endpoint",
          "vars": [
            {
              "name": "listen_port",
              "type": "integer",
              "title": "Listen Port",
              "description": "The port number to listen on.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 9559
            },
            {
              "name": "secret_header",
              "type": "text",
              "title": "Secret Header",
              "description": "The header to check for a specific value specified by `secret.value`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "secret_value",
              "type": "password",
              "title": "Secret Value",
              "description": "The secret stored in the header name specified by `secret.header`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "gigamon-ami"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve custom fields for all ECS mappings.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "http_endpoint.yml.hbs",
          "title": "Gigamon Application Metadata Intelligence (AMI) Logs",
          "description": "Collect the Gigamon Application Metadata Attributes which is in json format via HTTP endpoint.",
          "enabled": true,
          "ingestion_method": "Webhook"
        },
        {
          "input": "udp",
          "vars": [
            {
              "name": "listen_address",
              "type": "text",
              "title": "Listen Address",
              "description": "The bind address to listen for UDP connections. Set to \"0.0.0.0\" to bind to all available interfaces.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "localhost"
            },
            {
              "name": "listen_port",
              "type": "integer",
              "title": "Listen Port",
              "description": "The UDP port to listen for traffic.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 9560
            },
            {
              "name": "decode_cef_timezone",
              "type": "text",
              "title": "CEF Timezone",
              "description": "IANA time zone or time offset (e.g. `+0200`) to use when interpreting timestamps without a time zone in the CEF message.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "A list of tags to include in events. Including `forwarded` indicates that the events did not originate on this host and causes `host.name` to not be added to events.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "cef",
                "forwarded"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "udp_options",
              "type": "yaml",
              "title": "Custom UDP Options",
              "description": "Specify custom configuration options for the UDP input.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#read_buffer: 100MiB\n#max_message_size: 50KiB\n#timeout: 300s\n"
            },
            {
              "name": "preprocessors",
              "type": "yaml",
              "title": "Pre-Processors",
              "description": "Pre-processors are run before the CEF message is decoded. They can be used to correct CEF formatting inconsistencies that may exist from some sources. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_empty_values",
              "type": "bool",
              "title": "Ignore Empty Values",
              "description": "Ignore CEF fields that are empty. The alternative behavior is to treat an empty field as an error.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            }
          ],
          "template_path": "udp.yml.hbs",
          "title": "Gigamon CEF logs",
          "description": "Collect Gigamon CEF logs using udp input",
          "enabled": true,
          "ingestion_method": "Network Protocol"
        }
      ],
      "package": "gigamon",
      "path": "ami"
    }
  ]
}
