{
  "name": "trellix_epo_cloud",
  "title": "Trellix ePO Cloud",
  "version": "1.16.1",
  "release": "ga",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Collect logs from Trellix ePO Cloud with Elastic Agent.",
  "type": "integration",
  "download": "/epr/trellix_epo_cloud/trellix_epo_cloud-1.16.1.zip",
  "path": "/package/trellix_epo_cloud/1.16.1",
  "icons": [
    {
      "src": "/img/trellix-logo.svg",
      "path": "/package/trellix_epo_cloud/1.16.1/img/trellix-logo.svg",
      "title": "Trellix logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "edr_xdr",
    "siem"
  ],
  "signature_path": "/epr/trellix_epo_cloud/trellix_epo_cloud-1.16.1.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/trellix_epo_cloud/1.16.1/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/trellix-epo-cloud-device-dashboard.png",
      "path": "/package/trellix_epo_cloud/1.16.1/img/trellix-epo-cloud-device-dashboard.png",
      "title": "Trellix ePO Cloud Device Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/trellix-epo-cloud-event-dashboard.png",
      "path": "/package/trellix_epo_cloud/1.16.1/img/trellix-epo-cloud-event-dashboard.png",
      "title": "Trellix ePO Cloud Event Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/trellix-epo-cloud-group-dashboard.png",
      "path": "/package/trellix_epo_cloud/1.16.1/img/trellix-epo-cloud-group-dashboard.png",
      "title": "Trellix ePO Cloud Group Screenshot",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/trellix_epo_cloud/1.16.1/LICENSE.txt",
    "/package/trellix_epo_cloud/1.16.1/changelog.yml",
    "/package/trellix_epo_cloud/1.16.1/manifest.yml",
    "/package/trellix_epo_cloud/1.16.1/validation.yml",
    "/package/trellix_epo_cloud/1.16.1/docs/README.md",
    "/package/trellix_epo_cloud/1.16.1/img/trellix-epo-cloud-device-dashboard.png",
    "/package/trellix_epo_cloud/1.16.1/img/trellix-epo-cloud-event-dashboard.png",
    "/package/trellix_epo_cloud/1.16.1/img/trellix-epo-cloud-group-dashboard.png",
    "/package/trellix_epo_cloud/1.16.1/img/trellix-logo.svg",
    "/package/trellix_epo_cloud/1.16.1/kibana/tags.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/manifest.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/sample_event.json",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/manifest.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/sample_event.json",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/manifest.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/sample_event.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/dashboard/trellix_epo_cloud-1ea0a5c0-dad4-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/dashboard/trellix_epo_cloud-4ec166e0-daca-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/dashboard/trellix_epo_cloud-f6d8d960-dad1-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/search/trellix_epo_cloud-213b4440-dac8-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/search/trellix_epo_cloud-25ffa5f0-dacf-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/search/trellix_epo_cloud-48be5bf0-dac9-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/search/trellix_epo_cloud-7ba096f0-dad3-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/search/trellix_epo_cloud-7ba643a0-dad0-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/kibana/search/trellix_epo_cloud-8cdedff0-dad1-11ed-ab03-710ec626b54b.json",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/fields/base-fields.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/fields/beats.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/fields/fields.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/fields/base-fields.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/fields/beats.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/fields/fields.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/fields/base-fields.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/fields/beats.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/fields/fields.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/agent/stream/input.yml.hbs",
    "/package/trellix_epo_cloud/1.16.1/data_stream/device/elasticsearch/ingest_pipeline/default.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/agent/stream/input.yml.hbs",
    "/package/trellix_epo_cloud/1.16.1/data_stream/event/elasticsearch/ingest_pipeline/default.yml",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/agent/stream/input.yml.hbs",
    "/package/trellix_epo_cloud/1.16.1/data_stream/group/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "trellix_epo_cloud",
      "title": "Trellix ePO Cloud logs",
      "description": "Collect Trellix ePO Cloud logs.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "client_id",
              "type": "text",
              "title": "Client ID",
              "description": "Client ID for the Trellix ePO Cloud.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "client_secret",
              "type": "password",
              "title": "Client Secret",
              "description": "Client Secret for the Trellix ePO Cloud.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "API Key",
              "description": "API Key used to authenticate the requests.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the Trellix ePO Cloud API.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://api.manage.trellix.com"
            },
            {
              "name": "token_url",
              "type": "text",
              "title": "Token URL",
              "description": "Token URL of Trellix.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://iam.mcafee-cloud.com/iam/v1.1/token"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect Trellix ePO Cloud logs via API",
          "description": "Collecting Trellix ePO Cloud via API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "trellix_epo_cloud.device",
      "title": "Collect Device logs from Trellix ePO Cloud.",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Trellix ePO Cloud API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the Trellix ePO Cloud API. The maximum supported batch size value is 1000.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "trellix_epo_cloud-device"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve trellix_epo_cloud.device fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "input.yml.hbs",
          "title": "Device logs",
          "description": "Collect device logs from Trellix ePO Cloud.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "trellix_epo_cloud",
      "path": "device"
    },
    {
      "type": "logs",
      "dataset": "trellix_epo_cloud.event",
      "title": "Collect Event logs from Trellix ePO Cloud.",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the Event logs from Trellix ePO Cloud. The data retention period for events available via this API is 3 days. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Trellix ePO Cloud API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the Trellix ePO Cloud API. The maximum supported batch size value is 1000.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "trellix_epo_cloud-event"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve trellix_epo_cloud.event fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "input.yml.hbs",
          "title": "Event logs",
          "description": "Collect event logs from Trellix ePO Cloud.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "trellix_epo_cloud",
      "path": "event"
    },
    {
      "type": "logs",
      "dataset": "trellix_epo_cloud.group",
      "title": "Collect Group logs from Trellix ePO Cloud.",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Trellix ePO Cloud API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the Trellix ePO Cloud API. The maximum supported batch size value is 1000.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "trellix_epo_cloud-group"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve trellix_epo_cloud.group fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "input.yml.hbs",
          "title": "Group logs",
          "description": "Collect group logs from Trellix ePO Cloud.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "trellix_epo_cloud",
      "path": "group"
    }
  ]
}
