-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update ExtraHop Integration #4852
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
- full featured integration includes new and improved commands
- playbook framework for ExtraHop Detection incident type - updated test playbook - enhanced Endpoint Enrichment playbook to include ExtraHop
- unquoted = in playbook yml - detaileddescription in integration yml
- add 'secrets' to whitelist - move script to folder - add tests to playbooks and scripts - add descriptions to all playbook tasks - update integration argument display names
- lint issue - add script key to yml - only failure should be known/expected backwards compatibility breakage
- updated references in playbooks and script - need to deprecate old ExtraHop integration
Update ExtraHop Integration
yaakovi
approved these changes
Nov 11, 2019
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
force merge (failed on new incident field name)
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Original External PR
external pull request
Status
Ready
Related Issues
Description
New version of the ExtraHop integration (full featured). Complete content package with new powerful commands, real-time incident creation via REST, associated playbooks, enhanced system playbook, end-to-end ticket tracking through a playbook and a field trigger script. This is an ExtraHop supported integration that has been in the works as a partnership since last year, most recently we've been working with:
Screenshots
Related PRs
Required version of Demisto
4.5
Does it break backward compatibility?
Deprecate old ExtraHop integration?
Must have
Dependencies
Additional changes
Technical writer review
Mention and link to the files that require a technical writer review.