{
  "name": "ti_flashpoint",
  "title": "Flashpoint",
  "version": "0.4.0",
  "release": "beta",
  "description": "Collect logs from Flashpoint with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_flashpoint/ti_flashpoint-0.4.0.zip",
  "path": "/package/ti_flashpoint/0.4.0",
  "icons": [
    {
      "src": "/img/ti_flashpoint-logo.svg",
      "path": "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-logo.svg",
      "title": "Flashpoint logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.18.0 || ^9.0.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_flashpoint/ti_flashpoint-0.4.0.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_flashpoint/0.4.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/ti_flashpoint-alerts_dashboard.png",
      "path": "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-alerts_dashboard.png",
      "title": "Alerts Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ti_flashpoint-indicators_dashboard.png",
      "path": "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-indicators_dashboard.png",
      "title": "Indicators Dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/ti_flashpoint-vulnerabilities_dashboard.png",
      "path": "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-vulnerabilities_dashboard.png",
      "title": "Vulnerabilities Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_flashpoint/0.4.0/LICENSE.txt",
    "/package/ti_flashpoint/0.4.0/changelog.yml",
    "/package/ti_flashpoint/0.4.0/manifest.yml",
    "/package/ti_flashpoint/0.4.0/validation.yml",
    "/package/ti_flashpoint/0.4.0/docs/README.md",
    "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-alerts_dashboard.png",
    "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-indicators_dashboard.png",
    "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-logo.svg",
    "/package/ti_flashpoint/0.4.0/img/ti_flashpoint-vulnerabilities_dashboard.png",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/manifest.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/sample_event.json",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/manifest.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/sample_event.json",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/manifest.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/sample_event.json",
    "/package/ti_flashpoint/0.4.0/kibana/dashboard/ti_flashpoint-467e6747-8c82-4bd6-8ba5-2ec3d0e3b826.json",
    "/package/ti_flashpoint/0.4.0/kibana/dashboard/ti_flashpoint-cfe7739d-dce8-46e0-9f7e-4d077bc5c7bc.json",
    "/package/ti_flashpoint/0.4.0/kibana/dashboard/ti_flashpoint-f080464d-6a61-42dc-bd9f-45665d5cda75.json",
    "/package/ti_flashpoint/0.4.0/kibana/search/ti_flashpoint-02229216-8fcd-4a07-8c65-782f455fcfab.json",
    "/package/ti_flashpoint/0.4.0/kibana/search/ti_flashpoint-279eadc8-e6f2-4a00-a5cf-f01bd434eb6e.json",
    "/package/ti_flashpoint/0.4.0/kibana/search/ti_flashpoint-78e2de59-5a14-4a7b-9328-69b9b310c0b7.json",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/fields/base-fields.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/fields/beats.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/fields/ecs.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/fields/fields.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/fields/base-fields.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/fields/beats.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/fields/ecs.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/fields/fields.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/fields/is-transform-source-true.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/fields/base-fields.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/fields/beats.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/fields/ecs.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/fields/fields.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/fields/vulnerability.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/manifest.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/transform.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/agent/stream/cel.yml.hbs",
    "/package/ti_flashpoint/0.4.0/data_stream/alert/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/agent/stream/cel.yml.hbs",
    "/package/ti_flashpoint/0.4.0/data_stream/indicator/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/agent/stream/cel.yml.hbs",
    "/package/ti_flashpoint/0.4.0/data_stream/vulnerability/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/fields/base-fields.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/fields/beats.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/fields/ecs.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/fields/fields.yml",
    "/package/ti_flashpoint/0.4.0/elasticsearch/transform/latest_indicator/fields/is-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_flashpoint",
      "title": "Flashpoint",
      "description": "Collect logs from Flashpoint.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "url",
              "title": "URL",
              "description": "Base URL of the Flashpoint Instance.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://api.flashpoint.io"
            },
            {
              "name": "api_token",
              "type": "password",
              "title": "API Token",
              "description": "API Token to authenticate with Flashpoint API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect logs from Flashpoint API",
          "description": "Collecting logs via Flashpoint API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_flashpoint.alert",
      "title": "Alert",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the logs from Flashpoint API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Flashpoint API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page Size",
              "description": "Page size for the response of the Flashpoint API.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 5000
            },
            {
              "name": "max_executions",
              "type": "integer",
              "title": "Maximum Pages Per Interval",
              "description": "Maximum Pages Per Interval is the maximum number of pages that can be collected at each interval.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ti_flashpoint-alert"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve ti_flashpoint.alert fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Alert",
          "description": "Collect Alert logs from Flashpoint.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_flashpoint",
      "path": "alert"
    },
    {
      "type": "logs",
      "dataset": "ti_flashpoint.indicator",
      "title": "Indicator",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the logs from Flashpoint API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Flashpoint API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page Size",
              "description": "Page size for the response of the Flashpoint API.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "max_executions",
              "type": "integer",
              "title": "Maximum Pages Per Interval",
              "description": "Maximum Pages Per Interval is the maximum number of pages that can be collected at each interval.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ti_flashpoint-indicator"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve ti_flashpoint.indicator fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Indicator",
          "description": "Collect Indicator logs from Flashpoint.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_flashpoint",
      "path": "indicator"
    },
    {
      "type": "logs",
      "dataset": "ti_flashpoint.vulnerability",
      "title": "Vulnerability",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the logs from Flashpoint API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Flashpoint API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page Size",
              "description": "Page size for the response of the Flashpoint API.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "max_executions",
              "type": "integer",
              "title": "Maximum Pages Per Interval",
              "description": "Maximum Pages Per Interval is the maximum number of pages that can be collected at each interval.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "ti_flashpoint-vulnerability"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve ti_flashpoint.vulnerability fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Vulnerability",
          "description": "Collect Vulnerability logs from Flashpoint.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_flashpoint",
      "path": "vulnerability"
    }
  ]
}
