-
Notifications
You must be signed in to change notification settings - Fork 1.5k
DDS: Cato Networks: Crawler Integration v1.0.0 #22152
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
DDS: Cato Networks: Crawler Integration v1.0.0 #22152
Conversation
1a4bbb9 to
c418d7c
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| "manifest_version": "2.0.0", | ||
| "app_uuid": "4139f2e2-ba87-4e17-bcda-73bdade3ed8f", | ||
| "app_id": "cato-networks", | ||
| "display_on_public_website": false, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The new manifest omits the required owner field even though this is a v2.0.0 integration manifest; every other v2 manifest includes it for validation and ownership routing. Leaving it out will cause the manifest validator to fail and block publishing the integration.
Useful? React with 👍 / 👎.
| - groups: | ||
| - User | ||
| name: User Name | ||
| path: usr.name | ||
| source: log |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Facet fields used by events dashboard filters
The log config only facets DNS, geoip, and user fields here and never declares facets for the attributes the events dashboard filters on (event_sub_type, action, threat_type, application_name). Because unfaceted attributes are not indexed for search or group-bys, the dashboard’s template variables and widgets referencing those fields will stay empty even when relevant logs arrive.
Useful? React with 👍 / 👎.
|
Created DOCS-12937 for documentation team review |
cato_networks/README.md
Outdated
|
|
||
| This integration ingests the following logs: | ||
|
|
||
| - **Audit Logs**: This logs provide detailed information on admin actions performed within the system. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| - **Audit Logs**: This logs provide detailed information on admin actions performed within the system. | |
| - **Audit Logs**: These logs provide detailed information on admin actions performed within the system. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| This integration ingests the following logs: | ||
|
|
||
| - **Audit Logs**: This logs provide detailed information on admin actions performed within the system. | ||
| - **Events**: This logs provide detailed insights into security, detection and response, connectivity, and system events within the Cato Networks platform. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| - **Events**: This logs provide detailed insights into security, detection and response, connectivity, and system events within the Cato Networks platform. | |
| - **Events**: These logs provide detailed insights into security, detection and response, connectivity, and system events within the Cato Networks platform. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
rtrieu
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
left some minor feedback to comply with style guidelines.
cato_networks/README.md
Outdated
| 3. Click **Apply** button and copy the **Token**. | ||
| 4. Navigate to **Account** > **Account Info** and copy the **Account ID**. | ||
| 5. Identify your Cato Networks Region by checking the prefix of your URL: | ||
| - cc.us1.catonetworks.com - us1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| - cc.us1.catonetworks.com - us1 | |
| - `cc.us1.catonetworks.com` - us1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| 4. Navigate to **Account** > **Account Info** and copy the **Account ID**. | ||
| 5. Identify your Cato Networks Region by checking the prefix of your URL: | ||
| - cc.us1.catonetworks.com - us1 | ||
| - cc.catonetworks.com - Keep region as empty |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| - cc.catonetworks.com - Keep region as empty | |
| - `cc.catonetworks.com` - Keep region as empty |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| ### Event Log collection | ||
|
|
||
| #### Configure AWS S3 Bucket | ||
| **Note**: Please use **cato-networks** as the **S3 prefix**. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| **Note**: Please use **cato-networks** as the **S3 prefix**. | |
| When configuring the AWS bucket, use **cato-networks** as the **S3 prefix**. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
|
|
||
| #### Configure AWS S3 Bucket | ||
| **Note**: Please use **cato-networks** as the **S3 prefix**. | ||
| Please refer the [Configuring the AWS S3 Bucket][2] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Please refer the [Configuring the AWS S3 Bucket][2] | |
| For more information, see [Configuring the AWS S3 Bucket][2]. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| Please refer the [Configuring the AWS S3 Bucket][2] | ||
|
|
||
| #### Configure Event Integration in CATO Network | ||
| Please refer the [Adding Amazon S3 Integration for Events][3] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Please refer the [Adding Amazon S3 Integration for Events][3] | |
| For more information on configuring the event integration in a CATO network, see [Adding Amazon S3 Integration for Events][3]. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| Please refer the [Adding Amazon S3 Integration for Events][3] | ||
|
|
||
| #### Configure Datadog Forwarder | ||
| Please refer the [Datadog Forwarder][4] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Please refer the [Datadog Forwarder][4] | |
| See information on configuring the [Datadog Forwarder][4]. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| Please refer the [Datadog Forwarder][4] | ||
|
|
||
|
|
||
| ## Data Collected |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| ## Data Collected | |
| ## Data collected |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
cato_networks/README.md
Outdated
| **Note**: Please use **cato-networks** as the **S3 prefix**. | ||
| Please refer the [Configuring the AWS S3 Bucket][2] | ||
|
|
||
| #### Configure Event Integration in CATO Network |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| #### Configure Event Integration in CATO Network | |
| #### Set up event integration in CATO networks |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done 👍
What does this PR do?
This is a initial release PR of Cato Networks integration including all the required assets.
Integration Logo Source: https://www.catonetworks.com/wp-content/uploads/2024/07/cato-green-logo-2.svg
Additional Notes
Review checklist (to be filled by reviewers)
qa/skip-qalabel if the PR doesn't need to be tested during QA.backport/<branch-name>label to the PR and it will automatically open a backport PR once this one is merged