New Exchange Server integration#9197
New Exchange Server integration#9197marc-gr merged 9 commits intoelastic:mainfrom SimonKoetting:Exchange_Server
Conversation
Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
|
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
🚀 Benchmarks reportTo see the full report comment with |
taylor-swanson
left a comment
There was a problem hiding this comment.
I did an initial look over this, but I'll be diving deeper into the data streams next.
|
I feel like this integration would be better suited under the @elastic/sec-windows-platform team. @elastic/sec-deployment-and-devices primarily works with physical devices (routers, firewalls) where as this a Windows-exclusive application. While this currently reads from log files, I do believe Exchange can write to Windows Event Logs for at least some of its events, which would involve the winlog input. |
|
Hi @marc-gr |
|
/test |
💚 Build Succeeded
History
|
|
|
Package microsoft_exchange_server - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_exchange_server |
* initial commit new Exchange Server integration Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com> * Remove License file * change Codeowner * rename test-files for validation check * add validation.yml * Update Changelog, switch to filestream and fix docs * adjust manifest description * Change Codeowner * Added failure processors, switch to copy_from and remove duplicates --------- Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
* initial commit new Exchange Server integration Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com> * Remove License file * change Codeowner * rename test-files for validation check * add validation.yml * Update Changelog, switch to filestream and fix docs * adjust manifest description * Change Codeowner * Added failure processors, switch to copy_from and remove duplicates --------- Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
* initial commit new Exchange Server integration Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com> * Remove License file * change Codeowner * rename test-files for validation check * add validation.yml * Update Changelog, switch to filestream and fix docs * adjust manifest description * Change Codeowner * Added failure processors, switch to copy_from and remove duplicates --------- Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>

95.2% Coverage on New Code
0.0% Duplication on New Code
Initial push of new developed Microsoft Exchange Server Integration (on-prem)