Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update ExtraHop Integration #4852

Merged
merged 44 commits into from
Nov 11, 2019
Merged

Update ExtraHop Integration #4852

merged 44 commits into from
Nov 11, 2019

Conversation

content-bot
Copy link
Collaborator

Original External PR

external pull request

Status

Ready

Related Issues

Description

New version of the ExtraHop integration (full featured). Complete content package with new powerful commands, real-time incident creation via REST, associated playbooks, enhanced system playbook, end-to-end ticket tracking through a playbook and a field trigger script. This is an ExtraHop supported integration that has been in the works as a partnership since last year, most recently we've been working with:

  • Tyler R
  • Matt C
  • Prasen S
  • Marketing team

Screenshots

image

Related PRs

Required version of Demisto

4.5

Does it break backward compatibility?

  • No
    • This is a complete rewrite of the integration which consumes all existing command functionality, but renamed commands, inputs, and outputs. Renamed to be ExtraHop v2.

Deprecate old ExtraHop integration?

  • Yes

Must have

Dependencies

Additional changes

Technical writer review

Mention and link to the files that require a technical writer review.

Dan-at-Extrahop and others added 30 commits September 24, 2019 23:24
 - full featured integration includes new and improved commands
 - playbook framework for ExtraHop Detection incident type
 - updated test playbook
 - enhanced Endpoint Enrichment playbook to include ExtraHop
 - unquoted = in playbook yml
 - detaileddescription in integration yml
 - add 'secrets' to whitelist
 - move script to folder
 - add tests to playbooks and scripts
 - add descriptions to all playbook tasks
 - update integration argument display names
 - lint issue
 - add script key to yml
 - only failure should be known/expected backwards compatibility breakage
	- updated references in playbooks and script
	- need to deprecate old ExtraHop integration
Copy link
Contributor

@yaakovi yaakovi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

force merge (failed on new incident field name)

@yaakovi yaakovi merged commit 18874f9 into master Nov 11, 2019
@yaakovi yaakovi deleted the Dan-at-Extrahop_master_base branch November 11, 2019 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants