{
  "name": "ti_eclecticiq",
  "title": "EclecticIQ",
  "version": "1.7.2",
  "release": "ga",
  "description": "Ingest threat intelligence from EclecticIQ with Elastic Agent",
  "type": "integration",
  "download": "/epr/ti_eclecticiq/ti_eclecticiq-1.7.2.zip",
  "path": "/package/ti_eclecticiq/1.7.2",
  "icons": [
    {
      "src": "/img/logo_RGB.svg",
      "path": "/package/ti_eclecticiq/1.7.2/img/logo_RGB.svg",
      "title": "EIQ logo",
      "size": "133x43",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "partner",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_eclecticiq/ti_eclecticiq-1.7.2.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_eclecticiq/1.7.2/docs/README.md",
  "license": "basic",
  "assets": [
    "/package/ti_eclecticiq/1.7.2/LICENSE.txt",
    "/package/ti_eclecticiq/1.7.2/changelog.yml",
    "/package/ti_eclecticiq/1.7.2/manifest.yml",
    "/package/ti_eclecticiq/1.7.2/docs/README.md",
    "/package/ti_eclecticiq/1.7.2/img/logo_RGB.svg",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/manifest.yml",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/sample_event.json",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/fields/base-fields.yml",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/fields/ecs.yml",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/fields/fields.yml",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eclecticiq/1.7.2/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_eclecticiq/1.7.2/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/agent/stream/input.yml.hbs",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/elasticsearch/ilm/default_policy.json",
    "/package/ti_eclecticiq/1.7.2/data_stream/threat/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eclecticiq/1.7.2/elasticsearch/transform/latest_ioc/fields/base-fields.yml",
    "/package/ti_eclecticiq/1.7.2/elasticsearch/transform/latest_ioc/fields/ecs.yml",
    "/package/ti_eclecticiq/1.7.2/elasticsearch/transform/latest_ioc/fields/fields.yml",
    "/package/ti_eclecticiq/1.7.2/elasticsearch/transform/latest_ioc/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_eclecticiq",
      "title": "EclecticIQ",
      "description": "Collect data provided by EclecticIQ IC outgoing feeds.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "IC instance URL",
              "description": "Root URL of IC instance to download data from",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "token",
              "type": "password",
              "title": "API token",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "# certificate_authorities: |\n#   -----BEGIN CERTIFICATE-----\n#   MIID+jCCAuKgAwIBAgIGAJJMzlxLMA0GCSqGSIb3DQEBCwUAMHoxCzAJBgNVBAYT\n#   AlVTMQwwCgYDVQQKEwNJQk0xFjAUBgNVBAsTDURlZmF1bHROb2RlMDExFjAUBgNV\n#   BAsTDURlZmF1bHRDZWxsMDExGTAXBgNVBAsTEFJvb3QgQ2VydGlmaWNhdGUxEjAQ\n#   BgNVBAMTCWxvY2FsaG9zdDAeFw0yMTEyMTQyMjA3MTZaFw0yMjEyMTQyMjA3MTZa\n#   MF8xCzAJBgNVBAYTAlVTMQwwCgYDVQQKEwNJQk0xFjAUBgNVBAsTDURlZmF1bHRO\n#   b2RlMDExFjAUBgNVBAsTDURlZmF1bHRDZWxsMDExEjAQBgNVBAMTCWxvY2FsaG9z\n#   dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMv5HCsJZIpI5zCy+jXV\n#   z6lmzNc9UcVSEEHn86h6zT6pxuY90TYeAhlZ9hZ+SCKn4OQ4GoDRZhLPTkYDt+wW\n#   CV3NTIy9uCGUSJ6xjCKoxClJmgSQdg5m4HzwfY4ofoEZ5iZQ0Zmt62jGRWc0zuxj\n#   hegnM+eO2reBJYu6Ypa9RPJdYJsmn1RNnC74IDY8Y95qn+WZj//UALCpYfX41hko\n#   i7TWD9GKQO8SBmAxhjCDifOxVBokoxYrNdzESl0LXvnzEadeZTd9BfUtTaBHhx6t\n#   njqqCPrbTY+3jAbZFd4RiERPnhLVKMytw5ot506BhPrUtpr2lusbN5svNXjuLeea\n#   MMUCAwEAAaOBoDCBnTATBgNVHSMEDDAKgAhOatpLwvJFqjAdBgNVHSUEFjAUBggr\n#   BgEFBQcDAQYIKwYBBQUHAwIwVAYDVR0RBE0wS4E+UHJvZmlsZVVVSUQ6QXBwU3J2\n#   MDEtQkFTRS05MDkzMzJjMC1iNmFiLTQ2OTMtYWI5NC01Mjc1ZDI1MmFmNDiCCWxv\n#   Y2FsaG9zdDARBgNVHQ4ECgQITzqhA5sO8O4wDQYJKoZIhvcNAQELBQADggEBAKR0\n#   gY/BM69S6BDyWp5dxcpmZ9FS783FBbdUXjVtTkQno+oYURDrhCdsfTLYtqUlP4J4\n#   CHoskP+MwJjRIoKhPVQMv14Q4VC2J9coYXnePhFjE+6MaZbTjq9WaekGrpKkMaQA\n#   iQt5b67jo7y63CZKIo9yBvs7sxODQzDn3wZwyux2vPegXSaTHR/rop/s/mPk3YTS\n#   hQprs/IVtPoWU4/TsDN3gIlrAYGbcs29CAt5q9MfzkMmKsuDkTZD0ry42VjxjAmk\n#   xw23l/k8RoD1wRWaDVbgpjwSzt+kl+vJE/ip2w3h69eEZ9wbo6scRO5lCO2JM4Pr\n#   7RhLQyWn2u00L7/9Omw=\n#   -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Poll Outgoing feeds",
          "description": "Collects data from datasets sent by outgoing feeds"
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_eclecticiq.threat",
      "title": "Poll Outgoing feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "outgoing_feed_id",
              "type": "text",
              "title": "Outgoing feed ID",
              "description": "Download data from specified outgoing feed",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "update_strategy",
              "type": "select",
              "title": "Update strategy",
              "description": "Update strategy of the outgoing feed.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Period of fetching outgoing feed data, i.e. 1s/1m/1h.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "input.yml.hbs",
          "title": "Outgoing feed poll Configuration",
          "description": "Collects data from datasets in specified outgoing feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eclecticiq",
      "path": "threat"
    }
  ]
}
