Skip to content

New Exchange Server integration#9197

Merged
marc-gr merged 9 commits intoelastic:mainfrom
SimonKoetting:Exchange_Server
Mar 11, 2024
Merged

New Exchange Server integration#9197
marc-gr merged 9 commits intoelastic:mainfrom
SimonKoetting:Exchange_Server

Conversation

@SimonKoetting
Copy link
Copy Markdown
Contributor

Initial push of new developed Microsoft Exchange Server Integration (on-prem)

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
@SimonKoetting SimonKoetting changed the title initial commit new Exchange Server integration New Exchange Server integration Feb 20, 2024
@jamiehynds jamiehynds requested a review from a team February 20, 2024 11:17
@jamiehynds jamiehynds added New Integration Issue or pull request for creating a new integration package. Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Feb 20, 2024
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@elasticmachine
Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

Copy link
Copy Markdown
Contributor

@taylor-swanson taylor-swanson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I did an initial look over this, but I'll be diving deeper into the data streams next.

Comment thread packages/microsoft_exchange_server/changelog.yml Outdated
Comment thread packages/microsoft_exchange_server/manifest.yml Outdated
Comment thread packages/microsoft_exchange_server/img/sample-logo.svg Outdated
Comment thread packages/microsoft_exchange_server/img/sample-screenshot.png Outdated
Comment thread packages/microsoft_exchange_server/docs/README.md
Comment thread packages/microsoft_exchange_server/data_stream/smtp/manifest.yml Outdated
@taylor-swanson
Copy link
Copy Markdown
Contributor

I feel like this integration would be better suited under the @elastic/sec-windows-platform team.

@elastic/sec-deployment-and-devices primarily works with physical devices (routers, firewalls) where as this a Windows-exclusive application. While this currently reads from log files, I do believe Exchange can write to Windows Event Logs for at least some of its events, which would involve the winlog input.

@norrietaylor norrietaylor added the Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] label Feb 22, 2024
@jamiehynds jamiehynds requested a review from a team February 23, 2024 12:32
Comment thread .github/CODEOWNERS Outdated
Comment thread packages/microsoft_exchange_server/manifest.yml Outdated
@norrietaylor norrietaylor removed the Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] label Mar 5, 2024
Copy link
Copy Markdown
Contributor

@marc-gr marc-gr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking good! Just couple of observations to simplify the pipelines if it makes sense.

PS: added them to the first one, but they apply to all pipelines

Comment thread packages/microsoft_exchange_server/validation.yml
@marc-gr marc-gr self-assigned this Mar 6, 2024
@SimonKoetting
Copy link
Copy Markdown
Contributor Author

Hi @marc-gr
thanks for your report! Good points that I hadn't thought of.
The first 3 points are now implemented.

@SimonKoetting SimonKoetting requested a review from marc-gr March 8, 2024 14:47
@marc-gr
Copy link
Copy Markdown
Contributor

marc-gr commented Mar 11, 2024

/test

@marc-gr marc-gr enabled auto-merge (squash) March 11, 2024 08:56
@marc-gr marc-gr merged commit 0da0ea5 into elastic:main Mar 11, 2024
@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

History

cc @marc-gr @taylor-swanson

@elastic-sonarqube
Copy link
Copy Markdown

@elasticmachine
Copy link
Copy Markdown

Package microsoft_exchange_server - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_exchange_server

gizas pushed a commit that referenced this pull request Mar 13, 2024
* initial commit new Exchange Server integration

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>

* Remove License file

* change Codeowner

* rename test-files for validation check

* add validation.yml

* Update Changelog, switch to filestream and fix docs

* adjust manifest description

* Change Codeowner

* Added failure processors, switch to copy_from and remove duplicates

---------

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
@andrewkroh andrewkroh added the Integration:microsoft_exchange_server Microsoft Exchange Server (Community supported) label Jul 22, 2024
qcorporation pushed a commit that referenced this pull request Feb 3, 2025
* initial commit new Exchange Server integration

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>

* Remove License file

* change Codeowner

* rename test-files for validation check

* add validation.yml

* Update Changelog, switch to filestream and fix docs

* adjust manifest description

* Change Codeowner

* Added failure processors, switch to copy_from and remove duplicates

---------

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
qcorporation pushed a commit that referenced this pull request Feb 4, 2025
* initial commit new Exchange Server integration

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>

* Remove License file

* change Codeowner

* rename test-files for validation check

* add validation.yml

* Update Changelog, switch to filestream and fix docs

* adjust manifest description

* Change Codeowner

* Added failure processors, switch to copy_from and remove duplicates

---------

Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:microsoft_exchange_server Microsoft Exchange Server (Community supported) New Integration Issue or pull request for creating a new integration package. Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants