-
Notifications
You must be signed in to change notification settings - Fork 142
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create agent
Object, add agent
and owner
to endpoint
#987
Conversation
agent
Object, add agent
and owner
to device
agent
Object, add agent
and owner
to endpoint
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, thank you!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me
dcdba03
Please check the description of |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM.
This is a great addition for being able to natively use OCSF in an EDR.
Having homes for the agent identifier and the customer organization identifier is crucial.
@jonrau-at-queryai Looks good to me, just approved, but there is a small merge conflict with the CHANGELOG. Could you update that so we can merge? |
Signed-off-by: Jonathan Rau <[email protected]>
8caad44
Looks like it's fixed, but it bumped all of the approvals again. |
Signed-off-by: Jonathan Rau <[email protected]>
f902fef
Looks great! Thanks for this addition, its super useful! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Related Issue:
#986
Description of changes:
owner
todevice
,endpoint
, andnetwork_endpoint
.agent
object that defines various sensors and agent.agent
object todevice
,resource
, andendpoint
.is_applied
Boolean topolicy
.