{
  "name": "kolide",
  "title": "Kolide",
  "version": "0.2.0",
  "release": "beta",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Collect logs from Kolide (by 1Password) Device Trust with Elastic Agent.",
  "type": "integration",
  "download": "/epr/kolide/kolide-0.2.0.zip",
  "path": "/package/kolide/0.2.0",
  "icons": [
    {
      "src": "/img/kolide-logo.svg",
      "path": "/package/kolide/0.2.0/img/kolide-logo.svg",
      "title": "Kolide logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.0 || ^9.1.0"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/integration-experience"
  },
  "categories": [
    "security",
    "iam"
  ],
  "signature_path": "/epr/kolide/kolide-0.2.0.zip.sig",
  "format_version": "3.4.2",
  "readme": "/package/kolide/0.2.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/kolide-overview.png",
      "path": "/package/kolide/0.2.0/img/kolide-overview.png",
      "title": "Kolide Overview",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/kolide/0.2.0/LICENSE.txt",
    "/package/kolide/0.2.0/changelog.yml",
    "/package/kolide/0.2.0/manifest.yml",
    "/package/kolide/0.2.0/docs/README.md",
    "/package/kolide/0.2.0/img/kolide-logo.svg",
    "/package/kolide/0.2.0/img/kolide-overview.png",
    "/package/kolide/0.2.0/data_stream/audit/manifest.yml",
    "/package/kolide/0.2.0/data_stream/audit/sample_event.json",
    "/package/kolide/0.2.0/data_stream/auth/manifest.yml",
    "/package/kolide/0.2.0/data_stream/auth/sample_event.json",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/manifest.yml",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/sample_event.json",
    "/package/kolide/0.2.0/data_stream/device/manifest.yml",
    "/package/kolide/0.2.0/data_stream/device/sample_event.json",
    "/package/kolide/0.2.0/data_stream/device_check/manifest.yml",
    "/package/kolide/0.2.0/data_stream/device_check/sample_event.json",
    "/package/kolide/0.2.0/data_stream/issues/manifest.yml",
    "/package/kolide/0.2.0/data_stream/issues/sample_event.json",
    "/package/kolide/0.2.0/data_stream/osquery_result/manifest.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/sample_event.json",
    "/package/kolide/0.2.0/data_stream/osquery_status/manifest.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/sample_event.json",
    "/package/kolide/0.2.0/data_stream/people/manifest.yml",
    "/package/kolide/0.2.0/data_stream/people/sample_event.json",
    "/package/kolide/0.2.0/data_stream/request/manifest.yml",
    "/package/kolide/0.2.0/data_stream/request/sample_event.json",
    "/package/kolide/0.2.0/data_stream/webhook/manifest.yml",
    "/package/kolide/0.2.0/data_stream/webhook/routing_rules.yml",
    "/package/kolide/0.2.0/kibana/dashboard/kolide-56facae3-56fb-4637-aac5-961c69b0b4af.json",
    "/package/kolide/0.2.0/data_stream/audit/fields/agent.yml",
    "/package/kolide/0.2.0/data_stream/audit/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/audit/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/audit/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/audit/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/auth/fields/agent.yml",
    "/package/kolide/0.2.0/data_stream/auth/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/auth/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/auth/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/auth/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/device/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/device/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/device/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/device/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/device_check/fields/agent.yml",
    "/package/kolide/0.2.0/data_stream/device_check/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/device_check/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/device_check/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/device_check/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/issues/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/issues/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/issues/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/issues/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/fields/agent.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/fields/agent.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/people/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/people/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/people/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/people/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/request/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/request/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/request/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/request/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/webhook/fields/base-fields.yml",
    "/package/kolide/0.2.0/data_stream/webhook/fields/beats.yml",
    "/package/kolide/0.2.0/data_stream/webhook/fields/ecs.yml",
    "/package/kolide/0.2.0/data_stream/webhook/fields/fields.yml",
    "/package/kolide/0.2.0/data_stream/audit/agent/stream/aws-s3.yml.hbs",
    "/package/kolide/0.2.0/data_stream/audit/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/audit/agent/stream/gcs.yml.hbs",
    "/package/kolide/0.2.0/data_stream/audit/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/audit/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/audit/elasticsearch/ingest_pipeline/extended-mappings.yml",
    "/package/kolide/0.2.0/data_stream/audit/elasticsearch/ingest_pipeline/s3.yml",
    "/package/kolide/0.2.0/data_stream/audit/elasticsearch/ingest_pipeline/webhook.yml",
    "/package/kolide/0.2.0/data_stream/auth/agent/stream/aws-s3.yml.hbs",
    "/package/kolide/0.2.0/data_stream/auth/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/auth/agent/stream/gcs.yml.hbs",
    "/package/kolide/0.2.0/data_stream/auth/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/auth/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/auth/elasticsearch/ingest_pipeline/extended-mappings.yml",
    "/package/kolide/0.2.0/data_stream/auth/elasticsearch/ingest_pipeline/s3.yml",
    "/package/kolide/0.2.0/data_stream/auth/elasticsearch/ingest_pipeline/webhook.yml",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/deprovisioned_person/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/device/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/device/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/device/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/device/elasticsearch/ingest_pipeline/extended-mappings.yml",
    "/package/kolide/0.2.0/data_stream/device/elasticsearch/ingest_pipeline/webhook.yml",
    "/package/kolide/0.2.0/data_stream/device_check/agent/stream/aws-s3.yml.hbs",
    "/package/kolide/0.2.0/data_stream/device_check/agent/stream/gcs.yml.hbs",
    "/package/kolide/0.2.0/data_stream/device_check/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/device_check/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/issues/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/issues/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/issues/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/issues/elasticsearch/ingest_pipeline/extended-mappings.yml",
    "/package/kolide/0.2.0/data_stream/issues/elasticsearch/ingest_pipeline/webhook.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/agent/stream/aws-s3.yml.hbs",
    "/package/kolide/0.2.0/data_stream/osquery_result/agent/stream/gcs.yml.hbs",
    "/package/kolide/0.2.0/data_stream/osquery_result/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/osquery_result/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/agent/stream/aws-s3.yml.hbs",
    "/package/kolide/0.2.0/data_stream/osquery_status/agent/stream/gcs.yml.hbs",
    "/package/kolide/0.2.0/data_stream/osquery_status/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/osquery_status/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/people/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/people/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/request/agent/stream/cel.yml.hbs",
    "/package/kolide/0.2.0/data_stream/request/elasticsearch/ingest_pipeline/categorize.yml",
    "/package/kolide/0.2.0/data_stream/request/elasticsearch/ingest_pipeline/default.yml",
    "/package/kolide/0.2.0/data_stream/request/elasticsearch/ingest_pipeline/exemption.yml",
    "/package/kolide/0.2.0/data_stream/request/elasticsearch/ingest_pipeline/registration.yml",
    "/package/kolide/0.2.0/data_stream/request/elasticsearch/ingest_pipeline/webhook.yml",
    "/package/kolide/0.2.0/data_stream/webhook/agent/stream/http_endpoint.yml.hbs",
    "/package/kolide/0.2.0/data_stream/webhook/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "kolide",
      "title": "Kolide logs",
      "description": "Collect logs from Kolide via webhooks (HTTP endpoint), the REST API, and the Log Pipeline (AWS S3 or Google Cloud Storage).",
      "inputs": [
        {
          "type": "http_endpoint",
          "title": "Collect Kolide logs via webhooks",
          "description": "Collect Kolide events pushed to an HTTP endpoint (webhooks)."
        },
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "The base URL of the Kolide REST API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.kolide.com"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "API Key",
              "description": "Kolide API key used as a Bearer token. Create one in the Kolide console under Settings → Developers → API Keys. The value has the form `k2sk_v1_`.",
              "multi": false,
              "required": true,
              "show_user": true
            }
          ],
          "title": "Collect Kolide logs via the REST API",
          "description": "Collect Kolide events by polling the Kolide REST API."
        },
        {
          "type": "aws-s3",
          "vars": [
            {
              "name": "shared_credential_file",
              "type": "text",
              "title": "Shared Credential File",
              "description": "Directory of the shared credentials file used to read AWS credentials.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "credential_profile_name",
              "type": "text",
              "title": "Credential Profile Name",
              "description": "The profile name in the shared credentials file used to read AWS credentials.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "access_key_id",
              "type": "password",
              "title": "Access Key ID",
              "description": "The AWS access key ID the Elastic Agent uses to read from the bucket/queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "secret_access_key",
              "type": "password",
              "title": "Secret Access Key",
              "description": "The AWS secret access key the Elastic Agent uses to read from the bucket/queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "session_token",
              "type": "password",
              "title": "Session Token",
              "description": "The AWS session token for temporary (STS) credentials.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "role_arn",
              "type": "text",
              "title": "Role ARN",
              "description": "The IAM role ARN the Elastic Agent assumes to read the bucket/queue (for example, for cross-account access).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "endpoint",
              "type": "text",
              "title": "Endpoint",
              "description": "URL of the entry point for an AWS web service. Leave empty to use the default AWS endpoints.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            },
            {
              "name": "default_region",
              "type": "text",
              "title": "Default AWS Region",
              "description": "Default region to use before connecting to region-specific services if no region is set from the environment, credentials, or instance profile.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy AWS API connections, in the form of `http[s]://<user>:<password>@<server name/ip>:<port>`.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "Collect Kolide Log Pipeline data from AWS S3",
          "description": "Collect Kolide Log Pipeline data (authentication logs, audit logs, device check-run results, and raw osquery result/status logs) that Kolide writes to a customer-owned S3 bucket, via direct bucket polling or SQS notifications."
        },
        {
          "type": "gcs",
          "vars": [
            {
              "name": "project_id",
              "type": "text",
              "title": "Project ID",
              "description": "The GCP project ID the GCS bucket belongs to. Required to collect via GCS.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "service_account_key",
              "type": "password",
              "title": "Service Account Key",
              "description": "The GCP service account JSON key contents the Elastic Agent uses to read from the bucket. The service account only needs read access (for example, the `Storage Object Viewer` role). Alternative to the Service Account File; leave both empty to use Application Default Credentials (Workload Identity).",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "service_account_file",
              "type": "text",
              "title": "Service Account File",
              "description": "Path on the Elastic Agent host to a GCP service account JSON key file used to read from the bucket. Alternative to the Service Account Key.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "alternative_host",
              "type": "text",
              "title": "Alternative Host",
              "description": "Overrides the default host for the storage client (default is `storage.googleapis.com`). Used for testing against GCS emulators.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "Collect Kolide Log Pipeline data from Google Cloud Storage",
          "description": "Collect Kolide Log Pipeline data (authentication logs, audit logs, device check-run results, and raw osquery result/status logs) that Kolide writes to a customer-owned GCS bucket, via bucket polling."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "beta"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "kolide.audit",
      "title": "audit",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look the first time the integration runs. Supports seconds, minutes, and hours (for example, 24h, 720h). Days (d) are not supported.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-audit"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide audit logs via the REST API",
          "description": "Collect Kolide audit logs from the Kolide REST API (GET /audit_logs).",
          "enabled": true,
          "ingestion_method": "API"
        },
        {
          "input": "aws-s3",
          "vars": [
            {
              "name": "queue_url",
              "type": "text",
              "title": "[SQS] Queue URL",
              "description": "URL of the AWS SQS queue that S3 object-created notifications are delivered to. Set this to collect via SQS notifications. Leave empty to poll the bucket directly. For SQS, configure the bucket notification to deliver only the `audit_logs/` prefix to this queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "bucket_arn",
              "type": "text",
              "title": "[S3] Bucket ARN",
              "description": "ARN of the S3 bucket to poll directly (for example, `arn:aws:s3:::kolide-bucket`). Used when no Queue URL is set.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "access_point_arn",
              "type": "text",
              "title": "[S3] Access Point ARN",
              "description": "ARN of the S3 Access Point to poll directly. Alternative to the Bucket ARN.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "non_aws_bucket_name",
              "type": "text",
              "title": "[S3] Non-AWS Bucket Name",
              "description": "Name of the bucket to poll for 3rd-party S3-compatible services.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "region",
              "type": "text",
              "title": "[S3] Region",
              "description": "Region of the non-AWS S3-compatible endpoint. Required when a non-AWS bucket name is configured.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_list_prefix",
              "type": "text",
              "title": "[S3] Bucket List Prefix",
              "description": "Prefix used to list objects in the bucket (polling mode). Defaults to the Kolide Log Pipeline prefix for this data type.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "kolide/audit_logs/"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[S3/SQS] Number of Workers",
              "description": "Number of workers that will process the S3 objects or SQS messages.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 5
            },
            {
              "name": "bucket_list_interval",
              "type": "text",
              "title": "[S3] Bucket List Interval",
              "description": "Time interval for polling the listing of the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "start_timestamp",
              "type": "text",
              "title": "[S3] Start Timestamp",
              "description": "If set, only read S3 objects with a last-modified timestamp newer than the given timestamp. Accepts a timestamp in `YYYY-MM-DDTHH:MM:SSZ` format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_older",
              "type": "text",
              "title": "[S3] Ignore Older Timespan",
              "description": "If set, ignore S3 objects whose last-modified time is older than this timespan. Accepts a duration like `48h`, `2h30m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "visibility_timeout",
              "type": "text",
              "title": "[SQS] Visibility Timeout",
              "description": "The duration that received messages are hidden from subsequent retrieve requests after being retrieved. The maximum is 12 hours.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "api_timeout",
              "type": "text",
              "title": "[SQS] API Timeout",
              "description": "The maximum duration of an AWS API call. The maximum is half of the visibility timeout value.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "sqs.max_receive_count",
              "type": "integer",
              "title": "[SQS] Maximum Receive Count",
              "description": "The maximum number of times an SQS message should be received (retried) before being deleted.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "sqs.wait_time",
              "type": "text",
              "title": "[SQS] Maximum Wait Time",
              "description": "The maximum duration an SQS `ReceiveMessage` call waits for a message before returning. The maximum is `20s`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "20s"
            },
            {
              "name": "max_number_of_messages",
              "type": "integer",
              "title": "[SQS] Maximum Concurrent SQS Messages",
              "description": "The maximum number of SQS messages that can be inflight at any time.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[S3] File Selectors",
              "description": "A list of selectors that limit which S3 objects are processed, matched against the object key. Useful in SQS mode when a single queue receives notifications for multiple prefixes.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "fips_enabled",
              "type": "bool",
              "title": "Enable S3 FIPS",
              "description": "Enabling this option changes the service name from `s3` to `s3-fips` for connecting to the correct service endpoint.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-audit-s3"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`aws-s3` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-aws-s3.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "aws-s3.yml.hbs",
          "title": "Kolide audit logs via AWS S3 (Log Pipeline)",
          "description": "Collect Kolide admin audit logs (the `audit_logs/` prefix) that the Kolide Log Pipeline writes to a customer-owned S3 bucket, via SQS notifications or direct bucket polling.",
          "enabled": false,
          "ingestion_method": "AWS S3"
        },
        {
          "input": "gcs",
          "vars": [
            {
              "name": "buckets",
              "type": "yaml",
              "title": "[GCS] Buckets",
              "description": "The list of GCS buckets to poll, as YAML. The attribute `name` is required; `number_of_workers` (as `max_workers`), `poll`, `poll_interval`, and `bucket_timeout` can also be set per bucket to override the global values. See the [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html#attrib-buckets) for details.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "# The bucket name is the Kolide Log Pipeline destination bucket.\n- name: kolide-log-pipeline\n"
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[GCS] File Selectors",
              "description": "A list of regex patterns that limit which GCS objects are processed, matched against the object key. Defaults to the Kolide Log Pipeline prefix for this data type; adjust it if you customized the object path template in the Kolide log destination.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "- regex: '^kolide/audit_logs/'\n"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[GCS] Number of Workers",
              "description": "Number of workers that will process the GCS objects, per bucket.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 3
            },
            {
              "name": "poll",
              "type": "bool",
              "title": "[GCS] Polling",
              "description": "Determines if the bucket is continuously polled for new objects.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": true
            },
            {
              "name": "poll_interval",
              "type": "text",
              "title": "[GCS] Polling Interval",
              "description": "Time interval between polling operations.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "15s"
            },
            {
              "name": "bucket_timeout",
              "type": "text",
              "title": "[GCS] Bucket Timeout",
              "description": "Maximum time to wait for a bucket API response before timing out. Accepts a duration like `120s`, `2m`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "timestamp_epoch",
              "type": "integer",
              "title": "[GCS] Timestamp Epoch",
              "description": "If set, only process GCS objects whose last-modified time is newer than this Unix epoch time (in seconds).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-audit-gcs"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "gcs.yml.hbs",
          "title": "Kolide audit logs via Google Cloud Storage (Log Pipeline)",
          "description": "Collect Kolide admin audit logs (the `kolide/audit_logs/` prefix) that the Kolide Log Pipeline writes to a customer-owned GCS bucket, via bucket polling.",
          "enabled": false,
          "ingestion_method": "Google Cloud Storage"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "audit"
    },
    {
      "type": "logs",
      "dataset": "kolide.auth",
      "title": "auth",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look the first time the integration runs. Supports seconds, minutes, and hours (for example, 24h, 720h). Days (d) are not supported.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-auth"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide auth logs via the REST API",
          "description": "Collect Kolide SSO authentication sessions from the Kolide REST API (GET /auth_logs).",
          "enabled": true,
          "ingestion_method": "API"
        },
        {
          "input": "aws-s3",
          "vars": [
            {
              "name": "queue_url",
              "type": "text",
              "title": "[SQS] Queue URL",
              "description": "URL of the AWS SQS queue that S3 object-created notifications are delivered to. Set this to collect via SQS notifications. Leave empty to poll the bucket directly. For SQS, configure the bucket notification to deliver only the `auth_logs/` prefix to this queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "bucket_arn",
              "type": "text",
              "title": "[S3] Bucket ARN",
              "description": "ARN of the S3 bucket to poll directly (for example, `arn:aws:s3:::kolide-bucket`). Used when no Queue URL is set.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "access_point_arn",
              "type": "text",
              "title": "[S3] Access Point ARN",
              "description": "ARN of the S3 Access Point to poll directly. Alternative to the Bucket ARN.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "non_aws_bucket_name",
              "type": "text",
              "title": "[S3] Non-AWS Bucket Name",
              "description": "Name of the bucket to poll for 3rd-party S3-compatible services.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "region",
              "type": "text",
              "title": "[S3] Region",
              "description": "Region of the non-AWS S3-compatible endpoint. Required when a non-AWS bucket name is configured.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_list_prefix",
              "type": "text",
              "title": "[S3] Bucket List Prefix",
              "description": "Prefix used to list objects in the bucket (polling mode). Defaults to the Kolide Log Pipeline prefix for this data type.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "kolide/auth_logs/"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[S3/SQS] Number of Workers",
              "description": "Number of workers that will process the S3 objects or SQS messages.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 5
            },
            {
              "name": "bucket_list_interval",
              "type": "text",
              "title": "[S3] Bucket List Interval",
              "description": "Time interval for polling the listing of the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "start_timestamp",
              "type": "text",
              "title": "[S3] Start Timestamp",
              "description": "If set, only read S3 objects with a last-modified timestamp newer than the given timestamp. Accepts a timestamp in `YYYY-MM-DDTHH:MM:SSZ` format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_older",
              "type": "text",
              "title": "[S3] Ignore Older Timespan",
              "description": "If set, ignore S3 objects whose last-modified time is older than this timespan. Accepts a duration like `48h`, `2h30m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "visibility_timeout",
              "type": "text",
              "title": "[SQS] Visibility Timeout",
              "description": "The duration that received messages are hidden from subsequent retrieve requests after being retrieved. The maximum is 12 hours.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "api_timeout",
              "type": "text",
              "title": "[SQS] API Timeout",
              "description": "The maximum duration of an AWS API call. The maximum is half of the visibility timeout value.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "sqs.max_receive_count",
              "type": "integer",
              "title": "[SQS] Maximum Receive Count",
              "description": "The maximum number of times an SQS message should be received (retried) before being deleted.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "sqs.wait_time",
              "type": "text",
              "title": "[SQS] Maximum Wait Time",
              "description": "The maximum duration an SQS `ReceiveMessage` call waits for a message before returning. The maximum is `20s`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "20s"
            },
            {
              "name": "max_number_of_messages",
              "type": "integer",
              "title": "[SQS] Maximum Concurrent SQS Messages",
              "description": "The maximum number of SQS messages that can be inflight at any time.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[S3] File Selectors",
              "description": "A list of selectors that limit which S3 objects are processed, matched against the object key. Useful in SQS mode when a single queue receives notifications for multiple prefixes.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "fips_enabled",
              "type": "bool",
              "title": "Enable S3 FIPS",
              "description": "Enabling this option changes the service name from `s3` to `s3-fips` for connecting to the correct service endpoint.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-auth-s3"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`aws-s3` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-aws-s3.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "aws-s3.yml.hbs",
          "title": "Kolide auth logs via AWS S3 (Log Pipeline)",
          "description": "Collect Kolide authentication logs (the `auth_logs/` prefix) that the Kolide Log Pipeline writes to a customer-owned S3 bucket, via SQS notifications or direct bucket polling.",
          "enabled": false,
          "ingestion_method": "AWS S3"
        },
        {
          "input": "gcs",
          "vars": [
            {
              "name": "buckets",
              "type": "yaml",
              "title": "[GCS] Buckets",
              "description": "The list of GCS buckets to poll, as YAML. The attribute `name` is required; `number_of_workers` (as `max_workers`), `poll`, `poll_interval`, and `bucket_timeout` can also be set per bucket to override the global values. See the [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html#attrib-buckets) for details.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "# The bucket name is the Kolide Log Pipeline destination bucket.\n- name: kolide-log-pipeline\n"
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[GCS] File Selectors",
              "description": "A list of regex patterns that limit which GCS objects are processed, matched against the object key. Defaults to the Kolide Log Pipeline prefix for this data type; adjust it if you customized the object path template in the Kolide log destination.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "- regex: '^kolide/auth_logs/'\n"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[GCS] Number of Workers",
              "description": "Number of workers that will process the GCS objects, per bucket.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 3
            },
            {
              "name": "poll",
              "type": "bool",
              "title": "[GCS] Polling",
              "description": "Determines if the bucket is continuously polled for new objects.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": true
            },
            {
              "name": "poll_interval",
              "type": "text",
              "title": "[GCS] Polling Interval",
              "description": "Time interval between polling operations.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "15s"
            },
            {
              "name": "bucket_timeout",
              "type": "text",
              "title": "[GCS] Bucket Timeout",
              "description": "Maximum time to wait for a bucket API response before timing out. Accepts a duration like `120s`, `2m`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "timestamp_epoch",
              "type": "integer",
              "title": "[GCS] Timestamp Epoch",
              "description": "If set, only process GCS objects whose last-modified time is newer than this Unix epoch time (in seconds).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-auth-gcs"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "gcs.yml.hbs",
          "title": "Kolide authentication logs via Google Cloud Storage (Log Pipeline)",
          "description": "Collect Kolide authentication logs (the `kolide/auth_logs/` prefix) that the Kolide Log Pipeline writes to a customer-owned GCS bucket, via bucket polling.",
          "enabled": false,
          "ingestion_method": "Google Cloud Storage"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "auth"
    },
    {
      "type": "logs",
      "dataset": "kolide.deprovisioned_person",
      "title": "deprovisioned_person",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-deprovisioned-person"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide deprovisioned people via the REST API",
          "description": "Collect the full Kolide deprovisioned-people inventory from the Kolide REST\nAPI (GET /deprovisioned_people) on every poll. This is a separate resource\nfrom GET /people: it lists identities that have been offboarded/deprovisioned,\nnot the active people roster. The endpoint exposes no modified-since cursor,\nso each interval re-collects the complete collection; this full re-ingestion\nis intentional (not an interim limitation) since a delta/incremental approach\ncannot detect records that disappear from the list (e.g. re-provisioning or a\nKolide-side correction) or records missed due to pagination drift. The\ningest pipeline derives a content-fingerprint document `_id` (excluding\n`last_authenticated_at`) so byte-identical records are deduplicated across\npolls; records whose tracked fields change between polls are indexed as new\ndocuments rather than overwriting the prior one.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "deprovisioned_person"
    },
    {
      "type": "logs",
      "dataset": "kolide.device",
      "title": "device",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-device"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide devices via the REST API",
          "description": "Collect the full Kolide device inventory from the Kolide REST API (GET /devices)\non every poll. The /devices endpoint exposes no modified-since cursor, so each\ninterval re-collects the complete collection; the ingest pipeline assigns a\ncontent-based document `_id` so unchanged devices are deduplicated across polls\nand any change is captured as a new document.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "device"
    },
    {
      "type": "logs",
      "dataset": "kolide.device_check",
      "title": "Kolide device check-run results",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "aws-s3",
          "vars": [
            {
              "name": "queue_url",
              "type": "text",
              "title": "[SQS] Queue URL",
              "description": "URL of the AWS SQS queue that S3 object-created notifications are delivered to. Set this to collect via SQS notifications. Leave empty to poll the bucket directly. For SQS, configure the bucket notification to deliver only the `check_runs/` prefix to this queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "bucket_arn",
              "type": "text",
              "title": "[S3] Bucket ARN",
              "description": "ARN of the S3 bucket to poll directly (for example, `arn:aws:s3:::kolide-bucket`). Used when no Queue URL is set.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "access_point_arn",
              "type": "text",
              "title": "[S3] Access Point ARN",
              "description": "ARN of the S3 Access Point to poll directly. Alternative to the Bucket ARN.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "non_aws_bucket_name",
              "type": "text",
              "title": "[S3] Non-AWS Bucket Name",
              "description": "Name of the bucket to poll for 3rd-party S3-compatible services.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "region",
              "type": "text",
              "title": "[S3] Region",
              "description": "Region of the non-AWS S3-compatible endpoint. Required when a non-AWS bucket name is configured.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_list_prefix",
              "type": "text",
              "title": "[S3] Bucket List Prefix",
              "description": "Prefix used to list objects in the bucket (polling mode). Defaults to the Kolide Log Pipeline prefix for this data type.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "kolide/check_runs/"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[S3/SQS] Number of Workers",
              "description": "Number of workers that will process the S3 objects or SQS messages.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 5
            },
            {
              "name": "bucket_list_interval",
              "type": "text",
              "title": "[S3] Bucket List Interval",
              "description": "Time interval for polling the listing of the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "start_timestamp",
              "type": "text",
              "title": "[S3] Start Timestamp",
              "description": "If set, only read S3 objects with a last-modified timestamp newer than the given timestamp. Accepts a timestamp in `YYYY-MM-DDTHH:MM:SSZ` format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_older",
              "type": "text",
              "title": "[S3] Ignore Older Timespan",
              "description": "If set, ignore S3 objects whose last-modified time is older than this timespan. Accepts a duration like `48h`, `2h30m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "visibility_timeout",
              "type": "text",
              "title": "[SQS] Visibility Timeout",
              "description": "The duration that received messages are hidden from subsequent retrieve requests after being retrieved. The maximum is 12 hours.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "api_timeout",
              "type": "text",
              "title": "[SQS] API Timeout",
              "description": "The maximum duration of an AWS API call. The maximum is half of the visibility timeout value.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "sqs.max_receive_count",
              "type": "integer",
              "title": "[SQS] Maximum Receive Count",
              "description": "The maximum number of times an SQS message should be received (retried) before being deleted.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "sqs.wait_time",
              "type": "text",
              "title": "[SQS] Maximum Wait Time",
              "description": "The maximum duration an SQS `ReceiveMessage` call waits for a message before returning. The maximum is `20s`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "20s"
            },
            {
              "name": "max_number_of_messages",
              "type": "integer",
              "title": "[SQS] Maximum Concurrent SQS Messages",
              "description": "The maximum number of SQS messages that can be inflight at any time.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[S3] File Selectors",
              "description": "A list of selectors that limit which S3 objects are processed, matched against the object key. Useful in SQS mode when a single queue receives notifications for multiple prefixes.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "fips_enabled",
              "type": "bool",
              "title": "Enable S3 FIPS",
              "description": "Enabling this option changes the service name from `s3` to `s3-fips` for connecting to the correct service endpoint.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-device-check-s3"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`aws-s3` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-aws-s3.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "aws-s3.yml.hbs",
          "title": "Kolide device check-run results via AWS S3 (Log Pipeline)",
          "description": "Collect Kolide device check-run results (the `check_runs/` prefix) that the Kolide Log Pipeline writes to a customer-owned S3 bucket, via SQS notifications or direct bucket polling.",
          "enabled": false,
          "ingestion_method": "AWS S3"
        },
        {
          "input": "gcs",
          "vars": [
            {
              "name": "buckets",
              "type": "yaml",
              "title": "[GCS] Buckets",
              "description": "The list of GCS buckets to poll, as YAML. The attribute `name` is required; `number_of_workers` (as `max_workers`), `poll`, `poll_interval`, and `bucket_timeout` can also be set per bucket to override the global values. See the [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html#attrib-buckets) for details.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "# The bucket name is the Kolide Log Pipeline destination bucket.\n- name: kolide-log-pipeline\n"
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[GCS] File Selectors",
              "description": "A list of regex patterns that limit which GCS objects are processed, matched against the object key. Defaults to the Kolide Log Pipeline prefix for this data type; adjust it if you customized the object path template in the Kolide log destination.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "- regex: '^kolide/check_runs/'\n"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[GCS] Number of Workers",
              "description": "Number of workers that will process the GCS objects, per bucket.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 3
            },
            {
              "name": "poll",
              "type": "bool",
              "title": "[GCS] Polling",
              "description": "Determines if the bucket is continuously polled for new objects.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": true
            },
            {
              "name": "poll_interval",
              "type": "text",
              "title": "[GCS] Polling Interval",
              "description": "Time interval between polling operations.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "15s"
            },
            {
              "name": "bucket_timeout",
              "type": "text",
              "title": "[GCS] Bucket Timeout",
              "description": "Maximum time to wait for a bucket API response before timing out. Accepts a duration like `120s`, `2m`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "timestamp_epoch",
              "type": "integer",
              "title": "[GCS] Timestamp Epoch",
              "description": "If set, only process GCS objects whose last-modified time is newer than this Unix epoch time (in seconds).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-device-check-gcs"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "gcs.yml.hbs",
          "title": "Kolide device check-run results via Google Cloud Storage (Log Pipeline)",
          "description": "Collect Kolide device check-run results (the `kolide/check_runs/` prefix) that the Kolide Log Pipeline writes to a customer-owned GCS bucket, via bucket polling.",
          "enabled": false,
          "ingestion_method": "Google Cloud Storage"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "device_check"
    },
    {
      "type": "logs",
      "dataset": "kolide.issues",
      "title": "issues",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look the first time the integration runs. Supports seconds, minutes, and hours (for example, 24h, 720h). Days (d) are not supported.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-issues"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide device issues via the REST API",
          "description": "Collect Kolide device issues from the Kolide REST API (GET /issues).",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "issues"
    },
    {
      "type": "logs",
      "dataset": "kolide.osquery_result",
      "title": "Kolide osquery result logs",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "aws-s3",
          "vars": [
            {
              "name": "queue_url",
              "type": "text",
              "title": "[SQS] Queue URL",
              "description": "URL of the AWS SQS queue that S3 object-created notifications are delivered to. Set this to collect via SQS notifications. Leave empty to poll the bucket directly. For SQS, configure the bucket notification to deliver only the `results/` prefix to this queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "bucket_arn",
              "type": "text",
              "title": "[S3] Bucket ARN",
              "description": "ARN of the S3 bucket to poll directly (for example, `arn:aws:s3:::kolide-bucket`). Used when no Queue URL is set.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "access_point_arn",
              "type": "text",
              "title": "[S3] Access Point ARN",
              "description": "ARN of the S3 Access Point to poll directly. Alternative to the Bucket ARN.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "non_aws_bucket_name",
              "type": "text",
              "title": "[S3] Non-AWS Bucket Name",
              "description": "Name of the bucket to poll for 3rd-party S3-compatible services.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "region",
              "type": "text",
              "title": "[S3] Region",
              "description": "Region of the non-AWS S3-compatible endpoint. Required when a non-AWS bucket name is configured.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_list_prefix",
              "type": "text",
              "title": "[S3] Bucket List Prefix",
              "description": "Prefix used to list objects in the bucket (polling mode). Defaults to the Kolide Log Pipeline prefix for this data type. Kolide's full path template additionally nests `{{pack_name}}/{{query_name}}/device-{{device_id}}/...` under this prefix; the default still matches all of it since this is a prefix match, not an exact path.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "kolide/results/"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[S3/SQS] Number of Workers",
              "description": "Number of workers that will process the S3 objects or SQS messages.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 5
            },
            {
              "name": "bucket_list_interval",
              "type": "text",
              "title": "[S3] Bucket List Interval",
              "description": "Time interval for polling the listing of the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "start_timestamp",
              "type": "text",
              "title": "[S3] Start Timestamp",
              "description": "If set, only read S3 objects with a last-modified timestamp newer than the given timestamp. Accepts a timestamp in `YYYY-MM-DDTHH:MM:SSZ` format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_older",
              "type": "text",
              "title": "[S3] Ignore Older Timespan",
              "description": "If set, ignore S3 objects whose last-modified time is older than this timespan. Accepts a duration like `48h`, `2h30m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "visibility_timeout",
              "type": "text",
              "title": "[SQS] Visibility Timeout",
              "description": "The duration that received messages are hidden from subsequent retrieve requests after being retrieved. The maximum is 12 hours.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "api_timeout",
              "type": "text",
              "title": "[SQS] API Timeout",
              "description": "The maximum duration of an AWS API call. The maximum is half of the visibility timeout value.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "sqs.max_receive_count",
              "type": "integer",
              "title": "[SQS] Maximum Receive Count",
              "description": "The maximum number of times an SQS message should be received (retried) before being deleted.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "sqs.wait_time",
              "type": "text",
              "title": "[SQS] Maximum Wait Time",
              "description": "The maximum duration an SQS `ReceiveMessage` call waits for a message before returning. The maximum is `20s`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "20s"
            },
            {
              "name": "max_number_of_messages",
              "type": "integer",
              "title": "[SQS] Maximum Concurrent SQS Messages",
              "description": "The maximum number of SQS messages that can be inflight at any time.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[S3] File Selectors",
              "description": "A list of selectors that limit which S3 objects are processed, matched against the object key. Useful in SQS mode when a single queue receives notifications for multiple prefixes.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "fips_enabled",
              "type": "bool",
              "title": "Enable S3 FIPS",
              "description": "Enabling this option changes the service name from `s3` to `s3-fips` for connecting to the correct service endpoint.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-osquery-result-s3"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`aws-s3` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-aws-s3.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "aws-s3.yml.hbs",
          "title": "Kolide osquery result logs via AWS S3 (Log Pipeline)",
          "description": "Collect raw osquery Result Logs (the `results/` prefix) that the Kolide Log Pipeline writes to a customer-owned S3 bucket, via SQS notifications or direct bucket polling. Includes both snapshot-query rows and differential (added/removed) rows.",
          "enabled": false,
          "ingestion_method": "AWS S3"
        },
        {
          "input": "gcs",
          "vars": [
            {
              "name": "buckets",
              "type": "yaml",
              "title": "[GCS] Buckets",
              "description": "The list of GCS buckets to poll, as YAML. The attribute `name` is required; `number_of_workers` (as `max_workers`), `poll`, `poll_interval`, and `bucket_timeout` can also be set per bucket to override the global values. See the [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html#attrib-buckets) for details.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "# The bucket name is the Kolide Log Pipeline destination bucket.\n- name: kolide-log-pipeline\n"
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[GCS] File Selectors",
              "description": "A list of regex patterns that limit which GCS objects are processed, matched against the object key. Defaults to the Kolide Log Pipeline prefix for this data type; adjust it if you customized the object path template in the Kolide log destination.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "- regex: '^kolide/results/'\n"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[GCS] Number of Workers",
              "description": "Number of workers that will process the GCS objects, per bucket.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 3
            },
            {
              "name": "poll",
              "type": "bool",
              "title": "[GCS] Polling",
              "description": "Determines if the bucket is continuously polled for new objects.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": true
            },
            {
              "name": "poll_interval",
              "type": "text",
              "title": "[GCS] Polling Interval",
              "description": "Time interval between polling operations.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "15s"
            },
            {
              "name": "bucket_timeout",
              "type": "text",
              "title": "[GCS] Bucket Timeout",
              "description": "Maximum time to wait for a bucket API response before timing out. Accepts a duration like `120s`, `2m`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "timestamp_epoch",
              "type": "integer",
              "title": "[GCS] Timestamp Epoch",
              "description": "If set, only process GCS objects whose last-modified time is newer than this Unix epoch time (in seconds).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-osquery-result-gcs"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "gcs.yml.hbs",
          "title": "Kolide osquery result logs via Google Cloud Storage (Log Pipeline)",
          "description": "Collect raw osquery Result Logs (the `kolide/results/` prefix) that the Kolide Log Pipeline writes to a customer-owned GCS bucket, via bucket polling. Includes both snapshot-query rows and differential (added/removed) rows.",
          "enabled": false,
          "ingestion_method": "Google Cloud Storage"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "osquery_result"
    },
    {
      "type": "logs",
      "dataset": "kolide.osquery_status",
      "title": "Kolide osquery status logs",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "aws-s3",
          "vars": [
            {
              "name": "queue_url",
              "type": "text",
              "title": "[SQS] Queue URL",
              "description": "URL of the AWS SQS queue that S3 object-created notifications are delivered to. Set this to collect via SQS notifications. Leave empty to poll the bucket directly. For SQS, configure the bucket notification to deliver only the `status/` prefix to this queue.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "bucket_arn",
              "type": "text",
              "title": "[S3] Bucket ARN",
              "description": "ARN of the S3 bucket to poll directly (for example, `arn:aws:s3:::kolide-bucket`). Used when no Queue URL is set.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "access_point_arn",
              "type": "text",
              "title": "[S3] Access Point ARN",
              "description": "ARN of the S3 Access Point to poll directly. Alternative to the Bucket ARN.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "non_aws_bucket_name",
              "type": "text",
              "title": "[S3] Non-AWS Bucket Name",
              "description": "Name of the bucket to poll for 3rd-party S3-compatible services.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "region",
              "type": "text",
              "title": "[S3] Region",
              "description": "Region of the non-AWS S3-compatible endpoint. Required when a non-AWS bucket name is configured.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "bucket_list_prefix",
              "type": "text",
              "title": "[S3] Bucket List Prefix",
              "description": "Prefix used to list objects in the bucket (polling mode). Defaults to the Kolide Log Pipeline prefix for this data type. Kolide's full path template additionally nests `device-{{device_id}}/...` under this prefix; the default still matches all of it since this is a prefix match, not an exact path.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "kolide/status/"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[S3/SQS] Number of Workers",
              "description": "Number of workers that will process the S3 objects or SQS messages.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 5
            },
            {
              "name": "bucket_list_interval",
              "type": "text",
              "title": "[S3] Bucket List Interval",
              "description": "Time interval for polling the listing of the S3 bucket.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "start_timestamp",
              "type": "text",
              "title": "[S3] Start Timestamp",
              "description": "If set, only read S3 objects with a last-modified timestamp newer than the given timestamp. Accepts a timestamp in `YYYY-MM-DDTHH:MM:SSZ` format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ignore_older",
              "type": "text",
              "title": "[S3] Ignore Older Timespan",
              "description": "If set, ignore S3 objects whose last-modified time is older than this timespan. Accepts a duration like `48h`, `2h30m`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "visibility_timeout",
              "type": "text",
              "title": "[SQS] Visibility Timeout",
              "description": "The duration that received messages are hidden from subsequent retrieve requests after being retrieved. The maximum is 12 hours.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "api_timeout",
              "type": "text",
              "title": "[SQS] API Timeout",
              "description": "The maximum duration of an AWS API call. The maximum is half of the visibility timeout value.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "sqs.max_receive_count",
              "type": "integer",
              "title": "[SQS] Maximum Receive Count",
              "description": "The maximum number of times an SQS message should be received (retried) before being deleted.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "sqs.wait_time",
              "type": "text",
              "title": "[SQS] Maximum Wait Time",
              "description": "The maximum duration an SQS `ReceiveMessage` call waits for a message before returning. The maximum is `20s`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "20s"
            },
            {
              "name": "max_number_of_messages",
              "type": "integer",
              "title": "[SQS] Maximum Concurrent SQS Messages",
              "description": "The maximum number of SQS messages that can be inflight at any time.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 5
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[S3] File Selectors",
              "description": "A list of selectors that limit which S3 objects are processed, matched against the object key. Useful in SQS mode when a single queue receives notifications for multiple prefixes.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "fips_enabled",
              "type": "bool",
              "title": "Enable S3 FIPS",
              "description": "Enabling this option changes the service name from `s3` to `s3-fips` for connecting to the correct service endpoint.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-osquery-status-s3"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`aws-s3` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-aws-s3.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "aws-s3.yml.hbs",
          "title": "Kolide osquery status logs via AWS S3 (Log Pipeline)",
          "description": "Collect raw osquery Status Logs (the `status/` prefix) that the Kolide Log Pipeline writes to a customer-owned S3 bucket, via SQS notifications or direct bucket polling. Osquery daemon status/telemetry logs (GLOG-style), not host inventory data.",
          "enabled": false,
          "ingestion_method": "AWS S3"
        },
        {
          "input": "gcs",
          "vars": [
            {
              "name": "buckets",
              "type": "yaml",
              "title": "[GCS] Buckets",
              "description": "The list of GCS buckets to poll, as YAML. The attribute `name` is required; `number_of_workers` (as `max_workers`), `poll`, `poll_interval`, and `bucket_timeout` can also be set per bucket to override the global values. See the [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html#attrib-buckets) for details.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "# The bucket name is the Kolide Log Pipeline destination bucket.\n- name: kolide-log-pipeline\n"
            },
            {
              "name": "file_selectors",
              "type": "yaml",
              "title": "[GCS] File Selectors",
              "description": "A list of regex patterns that limit which GCS objects are processed, matched against the object key. Defaults to the Kolide Log Pipeline prefix for this data type; adjust it if you customized the object path template in the Kolide log destination.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "- regex: '^kolide/status/'\n"
            },
            {
              "name": "number_of_workers",
              "type": "integer",
              "title": "[GCS] Number of Workers",
              "description": "Number of workers that will process the GCS objects, per bucket.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": 3
            },
            {
              "name": "poll",
              "type": "bool",
              "title": "[GCS] Polling",
              "description": "Determines if the bucket is continuously polled for new objects.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": true
            },
            {
              "name": "poll_interval",
              "type": "text",
              "title": "[GCS] Polling Interval",
              "description": "Time interval between polling operations.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": "15s"
            },
            {
              "name": "bucket_timeout",
              "type": "text",
              "title": "[GCS] Bucket Timeout",
              "description": "Maximum time to wait for a bucket API response before timing out. Accepts a duration like `120s`, `2m`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "timestamp_epoch",
              "type": "integer",
              "title": "[GCS] Timestamp Epoch",
              "description": "If set, only process GCS objects whose last-modified time is newer than this Unix epoch time (in seconds).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-osquery-status-gcs"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "custom",
              "type": "yaml",
              "title": "Custom configurations",
              "description": "Additional settings to be added to the configuration. Be careful using this as it might break the input. See [`gcs` input settings docs](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-gcs.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            }
          ],
          "template_path": "gcs.yml.hbs",
          "title": "Kolide osquery status logs via Google Cloud Storage (Log Pipeline)",
          "description": "Collect raw osquery Status Logs (the `kolide/status/` prefix) that the Kolide Log Pipeline writes to a customer-owned GCS bucket, via bucket polling. Osquery daemon status/telemetry logs (GLOG-style), not host inventory data.",
          "enabled": false,
          "ingestion_method": "Google Cloud Storage"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "osquery_status"
    },
    {
      "type": "logs",
      "dataset": "kolide.people",
      "title": "people",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-people"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide people via the REST API",
          "description": "Collect the full Kolide people inventory from the Kolide REST API (GET /people)\non every poll. The /people endpoint exposes no modified-since cursor, so each\ninterval re-collects the complete collection; the ingest pipeline derives a\ncontent-fingerprint document `_id` (excluding `last_authenticated_at`) so\nbyte-identical records are deduplicated across polls; records whose tracked\nfields change between polls are indexed as new documents rather than\noverwriting the prior one.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "people"
    },
    {
      "type": "logs",
      "dataset": "kolide.request",
      "title": "request",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How often the Kolide REST API is polled. Supports seconds, minutes, and hours.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Number of records to request per page (per_page, 1-100).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL of the proxy to use, for example `http://proxy:3128`.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "TLS settings. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-request"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Kolide requests via the REST API",
          "description": "Collect Kolide approval-workflow requests from the Kolide REST API\n(GET /exemption_requests and GET /registration_requests). The two\nendpoints are collected as snapshots and normalized into one data stream\nwith `kolide.request.type` set to `exemption` or `registration`.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "request"
    },
    {
      "type": "logs",
      "dataset": "kolide.webhook",
      "title": "webhook",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "http_endpoint",
          "vars": [
            {
              "name": "listen_address",
              "type": "text",
              "title": "Listen Address",
              "description": "Bind address for the HTTP listener. Use 0.0.0.0 to listen on all interfaces.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "localhost"
            },
            {
              "name": "listen_port",
              "type": "integer",
              "title": "Listen Port",
              "description": "Bind port for the HTTP listener.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 9550
            },
            {
              "name": "url",
              "type": "text",
              "title": "URL Path",
              "description": "The URL path to accept Kolide webhook requests on. Register this path in the Kolide webhook endpoint settings.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "/kolide/webhook"
            },
            {
              "name": "hmac_header",
              "type": "text",
              "title": "HMAC Header",
              "description": "The name of the header that contains the HMAC signature. Kolide places the signature in the `Authorization` header.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "Authorization"
            },
            {
              "name": "hmac_key",
              "type": "password",
              "title": "Webhook Signing Secret",
              "description": "The signing secret from the Kolide webhook endpoint settings. Kolide uses this to compute an HMAC-SHA256 signature over the raw request body and sends it in the `Authorization` header. Shown once when the endpoint is created in Kolide.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "hmac_type",
              "type": "text",
              "title": "HMAC Type",
              "description": "The hash algorithm used for HMAC comparison. Kolide uses `sha256`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "sha256"
            },
            {
              "name": "hmac_prefix",
              "type": "text",
              "title": "HMAC Prefix",
              "description": "The prefix for the signature value. Kolide sends a bare lowercase hex digest with no prefix, so leave this empty.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": ""
            },
            {
              "name": "secret_header",
              "type": "text",
              "title": "Webhook Identifier Header",
              "description": "The header Kolide uses to send the per-endpoint identifier. Kolide always uses `X-Kolide-Webhook-Identifier`.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "X-Kolide-Webhook-Identifier"
            },
            {
              "name": "secret_value",
              "type": "password",
              "title": "Webhook Identifier",
              "description": "The per-endpoint identifier value from the Kolide webhook settings. Kolide sends this in the `X-Kolide-Webhook-Identifier` header on every request.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve Original Event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "TLS",
              "description": "Options for enabling TLS for the listening webhook endpoint. See the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html) for a list of all options.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "enabled: false\ncertificate: \"/etc/pki/client/cert.pem\"\nkey: \"/etc/pki/client/cert.key\"\n"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to include in the published event.",
              "multi": true,
              "required": false,
              "show_user": false,
              "default": [
                "forwarded",
                "kolide-webhook"
              ]
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "http_endpoint.yml.hbs",
          "title": "Kolide events via webhooks",
          "description": "Receive all Kolide webhook events on a single endpoint. Events are automatically routed to the appropriate data stream (auth, issues, request, device, audit) based on the Kolide event type field.",
          "enabled": true,
          "ingestion_method": "Webhook"
        }
      ],
      "package": "kolide",
      "elasticsearch": {
        "index_template.mappings": {
          "subobjects": false
        },
        "ingest_pipeline.name": "default"
      },
      "path": "webhook"
    }
  ]
}
