{
  "name": "ti_cyware_intel_exchange",
  "title": "Cyware Intel Exchange",
  "version": "0.5.0",
  "release": "beta",
  "description": "Collect logs from Cyware Intel Exchange with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_cyware_intel_exchange/ti_cyware_intel_exchange-0.5.0.zip",
  "path": "/package/ti_cyware_intel_exchange/0.5.0",
  "icons": [
    {
      "src": "/img/cyware_logo.svg",
      "path": "/package/ti_cyware_intel_exchange/0.5.0/img/cyware_logo.svg",
      "title": "Sample logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.18.0 || ^9.0.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_cyware_intel_exchange/ti_cyware_intel_exchange-0.5.0.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_cyware_intel_exchange/0.5.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/cyware-indicator-dashboard.png",
      "path": "/package/ti_cyware_intel_exchange/0.5.0/img/cyware-indicator-dashboard.png",
      "title": "Indicator Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_cyware_intel_exchange/0.5.0/LICENSE.txt",
    "/package/ti_cyware_intel_exchange/0.5.0/changelog.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/manifest.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/validation.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/docs/README.md",
    "/package/ti_cyware_intel_exchange/0.5.0/img/cyware-indicator-dashboard.png",
    "/package/ti_cyware_intel_exchange/0.5.0/img/cyware_logo.svg",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/lifecycle.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/manifest.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/sample_event.json",
    "/package/ti_cyware_intel_exchange/0.5.0/kibana/dashboard/ti_cyware_intel_exchange-56ee88b2-39b0-44f1-a122-46ff83bdbcb0.json",
    "/package/ti_cyware_intel_exchange/0.5.0/kibana/search/ti_cyware_intel_exchange-d3c12e4c-1d77-4c81-8223-5f909ffb433f.json",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/fields/base-fields.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/fields/beats.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/fields/ecs.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/fields/fields.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/fields/is-transform-source-true.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/agent/stream/cel.yml.hbs",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/elasticsearch/ilm/default_policy.json",
    "/package/ti_cyware_intel_exchange/0.5.0/data_stream/indicator/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/fields/base-fields.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/fields/beats.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/fields/ecs.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/fields/fields.yml",
    "/package/ti_cyware_intel_exchange/0.5.0/elasticsearch/transform/latest_ioc/fields/is-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_cyware_intel_exchange",
      "title": "Cyware Intel Exchange",
      "description": "Collect indicator logs from Cyware Intel Exchange.",
      "inputs": [
        {
          "type": "cel",
          "title": "Collect Cyware Intel Exchange logs via API",
          "description": "Collecting Cyware Intel Exchange logs via API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_cyware_intel_exchange.indicator",
      "ilm_policy": "logs-ti_cyware_intel_exchange.indicator-default_policy",
      "title": "Collect Indicator logs from Cyware Intel Exchange",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL. The url must be in the format- https://<tenant_code>.cyware.com/ctixapi",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "access_id",
              "type": "text",
              "title": "Access ID",
              "description": "Access ID of the Cyware Intel Exchange API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "secret_key",
              "type": "password",
              "title": "Secret Key",
              "description": "Secret Key of the Cyware Intel Exchange API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the Indicator logs from Cyware Intel Exchange API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Cyware Intel Exchange API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the Cyware Intel Exchange API.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 500
            },
            {
              "name": "label_name",
              "type": "text",
              "title": "Label Name",
              "description": "Pass a tag name to filter data. All data associated the passed tag will be returned.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "Indicator is expired after this duration since its last modified timestamp. Use [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units) in days, hours, or minutes (e.g 10d). Default `90d`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve ti_cyware_intel_exchange.indicator fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ti_cyware_intel_exchange-indicator"
              ]
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Indicator",
          "description": "Collect Indicator logs from Cyware Intel Exchange.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_cyware_intel_exchange",
      "path": "indicator"
    }
  ]
}
