{
  "name": "ti_otx",
  "title": "AlienVault OTX",
  "version": "1.32.2",
  "release": "ga",
  "description": "Ingest threat intelligence indicators from AlienVault Open Threat Exchange (OTX) with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_otx/ti_otx-1.32.2.zip",
  "path": "/package/ti_otx/1.32.2",
  "icons": [
    {
      "src": "/img/otx.svg",
      "path": "/package/ti_otx/1.32.2/img/otx.svg",
      "title": "Alienvault OTX",
      "size": "216x216",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.16 || ^9.3.5"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_otx/ti_otx-1.32.2.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_otx/1.32.2/docs/README.md",
  "license": "basic",
  "assets": [
    "/package/ti_otx/1.32.2/LICENSE.txt",
    "/package/ti_otx/1.32.2/changelog.yml",
    "/package/ti_otx/1.32.2/manifest.yml",
    "/package/ti_otx/1.32.2/validation.yml",
    "/package/ti_otx/1.32.2/docs/README.md",
    "/package/ti_otx/1.32.2/img/otx.svg",
    "/package/ti_otx/1.32.2/kibana/tags.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/lifecycle.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/manifest.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/sample_event.json",
    "/package/ti_otx/1.32.2/data_stream/threat/manifest.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/sample_event.json",
    "/package/ti_otx/1.32.2/kibana/dashboard/ti_otx-7da241a0-71f3-11ec-9910-d1ceb8a1734b.json",
    "/package/ti_otx/1.32.2/kibana/dashboard/ti_otx-83b01770-71f3-11ec-9910-d1ceb8a1734b.json",
    "/package/ti_otx/1.32.2/kibana/dashboard/ti_otx-8957ff80-71f3-11ec-9910-d1ceb8a1734b.json",
    "/package/ti_otx/1.32.2/kibana/dashboard/ti_otx-b8cff1d0-5bc3-11ee-b268-039dec835103.json",
    "/package/ti_otx/1.32.2/kibana/tag/ti_otx-6bc35230-71fd-11ec-9910-d1ceb8a1734b.json",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/fields/base-fields.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/fields/beats.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/fields/ecs.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/fields/fields.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/fields/agent.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/fields/base-fields.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/fields/beats.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/fields/ecs.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/fields/fields.yml",
    "/package/ti_otx/1.32.2/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_otx/1.32.2/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/agent/stream/cel.yml.hbs",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/elasticsearch/ilm/default_policy.json",
    "/package/ti_otx/1.32.2/data_stream/pulses_subscribed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_otx/1.32.2/data_stream/threat/agent/stream/httpjson.yml.hbs",
    "/package/ti_otx/1.32.2/data_stream/threat/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_otx/1.32.2/elasticsearch/transform/latest_ioc/fields/fields.yml",
    "/package/ti_otx/1.32.2/elasticsearch/transform/latest_ioc/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_otx",
      "title": "Alienvault OTX",
      "description": "Ingest threat intelligence indicators from AlienVault Open Threat Exchange (OTX) with Elastic Agent.",
      "inputs": [
        {
          "type": "httpjson",
          "title": "Ingest threat intelligence indicators from Alienvault OTX via API",
          "description": "Ingest threat intelligence indicators from AlienVault Open Threat Exchange (OTX) with Elastic Agent using HTTPJSON."
        },
        {
          "type": "cel",
          "title": "Ingest threat intelligence indicators from Alienvault OTX via Subscribed Pulses API using CEL input",
          "description": "Ingest threat intelligence indicators from AlienVault Open Threat Exchange (OTX) with Elastic Agent using CEL."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_otx.pulses_subscribed",
      "ilm_policy": "logs-ti_otx.pulses_subscribed-default_policy",
      "title": "Alienvault OTX Subcribed Pulses",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Alienvault OTX API endpoint",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://otx.alienvault.com/api/v1/pulses/subscribed"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "API Key",
              "description": "The Alienvault OTX API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "first_interval",
              "type": "text",
              "title": "First Interval",
              "description": "Configures how far back in time the agent should retrieve data from the API in hours.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "400h"
            },
            {
              "name": "lookback_range",
              "type": "text",
              "title": "Lookback Range",
              "description": "How many hours to look back for each request, should not be smaller than the interval (default 5m).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "1h"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "OTX specified `expiration` value for the indicators. If an indicator doesn't contain `expiration` field, this will be its default expiration duration. Use [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units) in days, hours, or minutes (e.g 10d)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "otx-pulses_subscribed"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Alienvault OTX Subcribed Pulses",
          "description": "Collect Alienvault OTX Indicators from Subcribed Pulses API",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_otx",
      "path": "pulses_subscribed"
    },
    {
      "type": "logs",
      "dataset": "ti_otx.threat",
      "title": "Alienvault OTX logs",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "Alienvault OTX API endpoint",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://otx.alienvault.com/api/v1/indicators/export"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "api_token",
              "type": "password",
              "title": "API Token",
              "description": "The Alienvault OTX API token",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "first_interval",
              "type": "text",
              "title": "First Interval",
              "description": "Configures how far back in time the agent should retrieve data from the API in hours.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "400h"
            },
            {
              "name": "lookback_range",
              "type": "text",
              "title": "Lookback Range",
              "description": "How many hours to look back for each request, should not be smaller than the interval (default 5m).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "1h"
            },
            {
              "name": "types",
              "type": "text",
              "title": "Filter on indicator types",
              "description": "A comma separated list of indicator types to retrieve, example: 'domain,IPv4,hostname,url,FileHash-SHA256'",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": true
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "otx-threat"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Alienvault OTX logs",
          "description": "Collect Alienvault OTX logs",
          "enabled": false,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_otx",
      "path": "threat"
    }
  ]
}
