integrations-core icon indicating copy to clipboard operation
integrations-core copied to clipboard

[SIEMINT-72] DDS: Suricata Integration

Open tirthrajchaudhari-crest opened this issue 1 year ago • 1 comments

What does this PR do?

PR for a new integration Suricata 1.0.0

Additional Notes

-- OOTB detection rules JSON would be shared separately with the required teams as a part of separate repository . -- Since during the standard attribute remapping we are not preserving the source attributes as per suggested best practices, it would result in filters using these standard attributes populating the values of other integrations as well as per current datadog behaviour.

Review checklist (to be filled by reviewers)

  • [ ] Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • [ ] Changelog entries must be created for modifications to shipped code
  • [ ] Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
  • [ ] If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

tirthrajchaudhari-crest avatar Jun 19 '24 12:06 tirthrajchaudhari-crest

Created Jira card for Docs Team editorial review.

drichards-87 avatar Jun 25 '24 14:06 drichards-87

Putting screenshot of logs I tested, looks good to me. I let you double check @tirthrajchaudhari-crest

Screenshot 2024-07-04 at 13 24 51 Screenshot 2024-07-04 at 13 25 42 Screenshot 2024-07-04 at 13 25 52 Screenshot 2024-07-04 at 13 26 08 Screenshot 2024-07-04 at 13 26 00 Screenshot 2024-07-04 at 13 26 26

audesikorav avatar Jul 04 '24 11:07 audesikorav

Putting screenshot of logs I tested, looks good to me. I let you double check @tirthrajchaudhari-crest

Hi @audesikorav , I have checked the tested logs for pipeline, looks good to me as well

tirthrajchaudhari-crest avatar Jul 05 '24 07:07 tirthrajchaudhari-crest

Does this PR look good to merge?

bhargavnariyanicrest avatar Jul 23 '24 06:07 bhargavnariyanicrest

This PR looks good however, the dashboards need to be updated to align with the Datadog dashboard style.

jnhunsberger avatar Aug 05 '24 23:08 jnhunsberger

This PR looks good however, the dashboards need to be updated to align with the Datadog dashboard style.

Hi Jason, We have updated the dasboaards to align with Datadog dashboard style.

tirthrajchaudhari-crest avatar Aug 07 '24 06:08 tirthrajchaudhari-crest