Add device_event and product_event data streams to the trellix_epo_on_prem integration.
Collects Trellix ePO removable-media events from EEFFDeviceAllEventsView and product lifecycle events from EPOProductEvents via the ePO REST API (CEL input). Both use AutoID as the keyset cursor.
Includes:
CEL-based collection with keyset pagination
Ingest pipelines with ECS mappings (device., user., event.category: host for device events; host.*, package.name, event.outcome for product events)
Field definitions, pipeline and system tests, sample events, and documentation
Dashboards for event volume, trends, actions, device protection/models, and product outcomes/products
Part of #20363.
Add device_event and product_event data streams to the trellix_epo_on_prem integration.
Collects Trellix ePO removable-media events from EEFFDeviceAllEventsView and product lifecycle events from EPOProductEvents via the ePO REST API (CEL input). Both use AutoID as the keyset cursor.
Includes:
CEL-based collection with keyset pagination
Ingest pipelines with ECS mappings (device., user., event.category: host for device events; host.*, package.name, event.outcome for product events)
Field definitions, pipeline and system tests, sample events, and documentation
Dashboards for event volume, trends, actions, device protection/models, and product outcomes/products
Part of #20363.