{
  "name": "ti_eset",
  "title": "ESET Threat Intelligence",
  "version": "1.11.2",
  "release": "ga",
  "description": "Ingest threat intelligence indicators from ESET Threat Intelligence with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_eset/ti_eset-1.11.2.zip",
  "path": "/package/ti_eset/1.11.2",
  "icons": [
    {
      "src": "/img/eset-lozenge-color-rgb.svg",
      "path": "/package/ti_eset/1.11.2/img/eset-lozenge-color-rgb.svg",
      "title": "Sample logo",
      "size": "96x96",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.4 || ~9.0.7 || ^9.1.4"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "partner",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_eset/ti_eset-1.11.2.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_eset/1.11.2/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/overview.png",
      "path": "/package/ti_eset/1.11.2/img/overview.png",
      "title": "threat intelligence overview",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/files.png",
      "path": "/package/ti_eset/1.11.2/img/files.png",
      "title": "threat intelligence files",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/url-ip.png",
      "path": "/package/ti_eset/1.11.2/img/url-ip.png",
      "title": "threat intelligence domains, URLs and IPs",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_eset/1.11.2/LICENSE.txt",
    "/package/ti_eset/1.11.2/changelog.yml",
    "/package/ti_eset/1.11.2/manifest.yml",
    "/package/ti_eset/1.11.2/docs/README.md",
    "/package/ti_eset/1.11.2/img/eset-lozenge-color-rgb.svg",
    "/package/ti_eset/1.11.2/img/files.png",
    "/package/ti_eset/1.11.2/img/overview.png",
    "/package/ti_eset/1.11.2/img/url-ip.png",
    "/package/ti_eset/1.11.2/data_stream/apt/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/sample_event.json",
    "/package/ti_eset/1.11.2/data_stream/botnet/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/sample_event.json",
    "/package/ti_eset/1.11.2/data_stream/cc/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/sample_event.json",
    "/package/ti_eset/1.11.2/data_stream/domains/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/sample_event.json",
    "/package/ti_eset/1.11.2/data_stream/files/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/files/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/files/sample_event.json",
    "/package/ti_eset/1.11.2/data_stream/ip/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/sample_event.json",
    "/package/ti_eset/1.11.2/data_stream/url/lifecycle.yml",
    "/package/ti_eset/1.11.2/data_stream/url/manifest.yml",
    "/package/ti_eset/1.11.2/data_stream/url/sample_event.json",
    "/package/ti_eset/1.11.2/kibana/dashboard/ti_eset-402bf6b0-8194-11ee-a704-a3364df0a052.json",
    "/package/ti_eset/1.11.2/kibana/dashboard/ti_eset-4fc91930-819a-11ee-a704-a3364df0a052.json",
    "/package/ti_eset/1.11.2/kibana/dashboard/ti_eset-c27d91e0-819a-11ee-a704-a3364df0a052.json",
    "/package/ti_eset/1.11.2/kibana/dashboard/ti_eset-f608e350-8192-11ee-a704-a3364df0a052.json",
    "/package/ti_eset/1.11.2/kibana/tag/ti_eset-ed13a500-8192-11ee-a704-a3364df0a052.json",
    "/package/ti_eset/1.11.2/kibana/tag/ti_eset-security-solution-default.json",
    "/package/ti_eset/1.11.2/data_stream/apt/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/data_stream/files/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/files/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/files/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/files/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/files/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/data_stream/url/fields/agent.yml",
    "/package/ti_eset/1.11.2/data_stream/url/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/data_stream/url/fields/ecs.yml",
    "/package/ti_eset/1.11.2/data_stream/url/fields/fields.yml",
    "/package/ti_eset/1.11.2/data_stream/url/fields/is-ioc-transform-source-true.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/manifest.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/transform.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ingest_pipeline/pipeline-cert.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ingest_pipeline/pipeline-domain-ip.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ingest_pipeline/pipeline-email.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ingest_pipeline/pipeline-file.yml",
    "/package/ti_eset/1.11.2/data_stream/apt/elasticsearch/ingest_pipeline/pipeline-url.yml",
    "/package/ti_eset/1.11.2/data_stream/botnet/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/botnet/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/botnet/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/data_stream/cc/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/cc/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/cc/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/data_stream/domains/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/domains/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/domains/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/data_stream/files/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/files/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/files/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/data_stream/ip/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/ip/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/ip/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/data_stream/url/agent/stream/httpjson.yml.hbs",
    "/package/ti_eset/1.11.2/data_stream/url/elasticsearch/ilm/default_policy.json",
    "/package/ti_eset/1.11.2/data_stream/url/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/apt_latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/botnet_latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/cc_latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/domains_latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/files_latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/ip_latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/fields/agent.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/fields/base-fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/fields/ecs.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/fields/fields.yml",
    "/package/ti_eset/1.11.2/elasticsearch/transform/url_latest_ioc/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "eset",
      "title": "ETI feeds (TAXII version 2)",
      "description": "Collect data from ETI feeds (TAXII version 2)",
      "inputs": [
        {
          "type": "httpjson",
          "vars": [
            {
              "name": "username",
              "type": "text",
              "title": "ETI Username",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "password",
              "type": "password",
              "title": "ETI Password",
              "multi": false,
              "required": true,
              "show_user": true
            }
          ],
          "title": "ETI feeds (TAXII version 2)",
          "description": "Collect data from ETI feeds (TAXII version 2)"
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_eset.apt",
      "ilm_policy": "logs-ti_eset.apt-default_policy",
      "title": "APT",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of APT collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/97e3eb74ae5f46dd9e22f677a6938ee7/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-apt"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "APT",
          "description": "Collect data from ETI APT feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "apt"
    },
    {
      "type": "logs",
      "dataset": "ti_eset.botnet",
      "ilm_policy": "logs-ti_eset.botnet-default_policy",
      "title": "Botnet",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of Botnet collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/0abb06690b0b47e49cd7794396b76b20/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-botnet"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Botnet",
          "description": "Collect data from ETI Botnet feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "botnet"
    },
    {
      "type": "logs",
      "dataset": "ti_eset.cc",
      "ilm_policy": "logs-ti_eset.cc-default_policy",
      "title": "Botnet C&C",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of C&C collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/d1923a526e8f400dbb301259240ee3d5/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-cc"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Botnet C&C",
          "description": "Collect data from ETI Botnet C&C feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "cc"
    },
    {
      "type": "logs",
      "dataset": "ti_eset.domains",
      "ilm_policy": "logs-ti_eset.domains-default_policy",
      "title": "Domain",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of Domain collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/a34aa0a4f9de419582a883863503f9c4/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-domains"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Domain",
          "description": "Collect data from ETI Domain feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "domains"
    },
    {
      "type": "logs",
      "dataset": "ti_eset.files",
      "ilm_policy": "logs-ti_eset.files-default_policy",
      "title": "Malicious files",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of Malicious files collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/ee6a153ed77e4ec3ab21e76cc2074b9f/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-files"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Malicious files",
          "description": "Collect data from ETI Malicious file feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "files"
    },
    {
      "type": "logs",
      "dataset": "ti_eset.ip",
      "ilm_policy": "logs-ti_eset.ip-default_policy",
      "title": "IP",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of IP collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/baaed2a92335418aa753fe944e13c23a/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-ip"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "IP",
          "description": "Collect data from ETI IP feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "ip"
    },
    {
      "type": "logs",
      "dataset": "ti_eset.url",
      "ilm_policy": "logs-ti_eset.url-default_policy",
      "title": "URL",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Collection URL",
              "description": "URL with API root and identifier of URL collection as described by [TAXII v2.1 standard](https://docs.oasis-open.org/cti/taxii/v2.1/os/taxii-v2.1-os.html#_Toc31107514)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://taxii.eset.com/taxii2/643f4eb5-f8b7-46a3-a606-6d61d5ce223a/collections/1d3208c143be49da8130f5a66fd3a0fa/objects/"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1m"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to look for indicators the first time the agent is started. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "48h"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "1000"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "eset-url"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "URL",
          "description": "Collect data from ETI URL feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_eset",
      "path": "url"
    }
  ]
}
