{
  "name": "ti_anomali",
  "title": "Anomali ThreatStream",
  "version": "2.8.3",
  "release": "ga",
  "description": "Ingest threat intelligence indicators from Anomali ThreatStream with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_anomali/ti_anomali-2.8.3.zip",
  "path": "/package/ti_anomali/2.8.3",
  "icons": [
    {
      "src": "/img/anomali.svg",
      "path": "/package/ti_anomali/2.8.3/img/anomali.svg",
      "title": "Anomali ThreatStream",
      "size": "216x216",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.18.0 || ^9.0.0"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_anomali/ti_anomali-2.8.3.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_anomali/2.8.3/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/ti_anomali-overview-dashboard.png",
      "path": "/package/ti_anomali/2.8.3/img/ti_anomali-overview-dashboard.png",
      "title": "Dashboard: Anomali ThreatStream Overview",
      "size": "1279x1322",
      "type": "image/png"
    },
    {
      "src": "/img/ti_anomali-files-dashboard.png",
      "path": "/package/ti_anomali/2.8.3/img/ti_anomali-files-dashboard.png",
      "title": "Dashboard: Anomali ThreatStream Files",
      "size": "1279x1322",
      "type": "image/png"
    },
    {
      "src": "/img/ti_anomali-url-dashboard.png",
      "path": "/package/ti_anomali/2.8.3/img/ti_anomali-url-dashboard.png",
      "title": "Dashboard: Anomali ThreatStream URL",
      "size": "1279x1322",
      "type": "image/png"
    },
    {
      "src": "/img/ti_anomali-other-indicators-dashboard.png",
      "path": "/package/ti_anomali/2.8.3/img/ti_anomali-other-indicators-dashboard.png",
      "title": "Dashboard: Anomali ThreatStream Other Indicators",
      "size": "1279x1322",
      "type": "image/png"
    },
    {
      "src": "/img/ti_anomali-integration-dashboard.png",
      "path": "/package/ti_anomali/2.8.3/img/ti_anomali-integration-dashboard.png",
      "title": "Add Anomali ThreatStream integration",
      "size": "1268x1322",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_anomali/2.8.3/LICENSE.txt",
    "/package/ti_anomali/2.8.3/changelog.yml",
    "/package/ti_anomali/2.8.3/manifest.yml",
    "/package/ti_anomali/2.8.3/validation.yml",
    "/package/ti_anomali/2.8.3/docs/README.md",
    "/package/ti_anomali/2.8.3/img/anomali.svg",
    "/package/ti_anomali/2.8.3/img/ti_anomali-files-dashboard.png",
    "/package/ti_anomali/2.8.3/img/ti_anomali-integration-dashboard.png",
    "/package/ti_anomali/2.8.3/img/ti_anomali-other-indicators-dashboard.png",
    "/package/ti_anomali/2.8.3/img/ti_anomali-overview-dashboard.png",
    "/package/ti_anomali/2.8.3/img/ti_anomali-url-dashboard.png",
    "/package/ti_anomali/2.8.3/kibana/tags.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/lifecycle.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/manifest.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/sample_event.json",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/lifecycle.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/manifest.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/sample_event.json",
    "/package/ti_anomali/2.8.3/kibana/dashboard/ti_anomali-207f3c40-45fb-11ec-ab0c-d7f52dcaa020.json",
    "/package/ti_anomali/2.8.3/kibana/dashboard/ti_anomali-39699a60-45fc-11ec-ab0c-d7f52dcaa020.json",
    "/package/ti_anomali/2.8.3/kibana/dashboard/ti_anomali-78e08d20-45fc-11ec-ab0c-d7f52dcaa020.json",
    "/package/ti_anomali/2.8.3/kibana/dashboard/ti_anomali-96fe1e60-4261-11ec-b7be-d3026acdf1cf.json",
    "/package/ti_anomali/2.8.3/kibana/search/ti_anomali-2fcc2f21-fc8a-4538-a3b6-4bc0a3aa8137.json",
    "/package/ti_anomali/2.8.3/kibana/search/ti_anomali-6c7f16fd-525e-4180-bf65-9db143373d68.json",
    "/package/ti_anomali/2.8.3/kibana/search/ti_anomali-90451c29-e78a-454e-9bf9-2c0ee5fe413a.json",
    "/package/ti_anomali/2.8.3/kibana/search/ti_anomali-e23972f4-0b13-47c1-88b7-366e375eb35b.json",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/fields/base-fields.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/fields/beats.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/fields/fields.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/fields/is-ioc-transform-source-true.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/fields/base-fields.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/fields/beats.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/fields/fields.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/fields/is-ioc-transform-source-true.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/manifest.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/transform.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/agent/stream/cel.yml.hbs",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/elasticsearch/ilm/default_policy.json",
    "/package/ti_anomali/2.8.3/data_stream/intelligence/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/agent/stream/http_endpoint.yml.hbs",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/elasticsearch/ilm/default_policy.json",
    "/package/ti_anomali/2.8.3/data_stream/threatstream/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/fields/agent.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/fields/base-fields.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/fields/beats.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/fields/ecs.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/fields/fields.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_intelligence/fields/is-ioc-transform-source-false.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_ioc/fields/fields.yml",
    "/package/ti_anomali/2.8.3/elasticsearch/transform/latest_ioc/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_anomali",
      "title": "Anomali ThreatStream",
      "description": "Ingest threat intelligence indicators from Anomali ThreatStream with Elastic Agent.",
      "inputs": [
        {
          "type": "cel",
          "title": "Collect Anomali threat indicators using the Anomali ThreatStream API",
          "description": "Collect threat indicators from the intelligence endpoint of the Anomali ThreatStream API."
        },
        {
          "type": "http_endpoint",
          "title": "DEPRECATED - Collect Anomali threat indicators from ThreatStream using the Elastic Extension software",
          "description": "Please deactivate this option and instead use the one described above. This option collects Anomali threat indicators from ThreatStream using Elastic Extension software which is deprecated."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_anomali.intelligence",
      "ilm_policy": "logs-ti_anomali.intelligence-default_policy",
      "title": "Anomali ThreatStream",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "username",
              "type": "text",
              "title": "Username",
              "description": "The username for Anomali ThreatStream.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "API key",
              "description": "The API key for Anomali ThreatStream.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "The base URL of the Anomali ThreatStream instance.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.threatstream.com"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Anomali ThreatStream API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the indicators from Anomali ThreatStream API. Defaults to 2160h i.e., 90 days. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "2160h"
            },
            {
              "name": "ioc_duration_before_deletion",
              "type": "text",
              "title": "IOC Duration Before Deletion",
              "description": "All IOCs are deleted after this duration. This setting is required to avoid \"orphaned\" IOCs that never expire. If an earlier expiration time is set upstream, that will be used. Use [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units) to specify a duration in minutes, hours or days (e.g 10d).",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "query",
              "type": "text",
              "title": "Advanced Search Query",
              "description": "A complex filter to be applied when requesting data, similar to those used on the Advanced search screen of the ThreatStream UI. See \"Advanced Search Queries\" in the Anomali ThreatStream API Reference for more information.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "remote_api_true",
              "type": "bool",
              "title": "Get remote observables",
              "description": "Get remote observables (for ThreatStream OnPrem only). This attribute does not need to be set to retrieve local observables. Only use this when retrieving remote observables from ThreatStream Cloud.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page Size",
              "description": "The number of objects to return in each response. The maximum is 1000.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "anomali-intelligence"
              ]
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Threat Indicators",
          "description": "Collect threat indicators from the intelligence endpoint of the Anomali ThreatStream API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_anomali",
      "path": "intelligence"
    },
    {
      "type": "logs",
      "dataset": "ti_anomali.threatstream",
      "ilm_policy": "logs-ti_anomali.threatstream-default_policy",
      "title": "Anomali ThreatStream",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "http_endpoint",
          "vars": [
            {
              "name": "listen_address",
              "type": "text",
              "title": "Listen Address",
              "description": "Bind address for the listener. Use 0.0.0.0 to listen on all interfaces.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "localhost"
            },
            {
              "name": "listen_port",
              "type": "integer",
              "title": "Listen Port",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 8181
            },
            {
              "name": "url",
              "type": "text",
              "title": "Webhook path",
              "description": "URL path where the webhook will accept requests.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "/"
            },
            {
              "name": "content_type",
              "type": "text",
              "title": "Content Type",
              "description": "Expected Content-Type in HTTP request.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "application/x-ndjson"
            },
            {
              "name": "secret",
              "type": "password",
              "title": "HMAC secret key",
              "description": "Secret key to authenticate requests from the SDK.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "enabled: false\ncertificate: \"/etc/pki/client/cert.pem\"\nkey: \"/etc/pki/client/cert.key\"\n"
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "Enforces all IOCs to expire after this duration. This setting is required to avoid \"orphaned\" IOCs that never expire. Use [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units) in days, hours, or minutes (e.g 10d)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "anomali-threatstream"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "http_endpoint.yml.hbs",
          "title": "Threat Indicators",
          "description": "Deactivate this option and instead use the one described above. This option collects Anomali threat indicators from ThreatStream using Elastic Extension software which is deprecated.",
          "enabled": false,
          "ingestion_method": "Webhook"
        }
      ],
      "package": "ti_anomali",
      "path": "threatstream"
    }
  ]
}
