Skip to content

[trellix_epo_on_prem] Add support of Device Event and Product Event datastream. #20989

Description

@muskan-agarwal26

Add device_event and product_event data streams to the trellix_epo_on_prem integration.

Collects Trellix ePO removable-media events from EEFFDeviceAllEventsView and product lifecycle events from EPOProductEvents via the ePO REST API (CEL input). Both use AutoID as the keyset cursor.

Includes:

CEL-based collection with keyset pagination
Ingest pipelines with ECS mappings (device., user., event.category: host for device events; host.*, package.name, event.outcome for product events)
Field definitions, pipeline and system tests, sample events, and documentation
Dashboards for event volume, trends, actions, device protection/models, and product outcomes/products

Part of #20363.

Metadata

Metadata

Labels

New IntegrationIssue or pull request for creating a new integration package.Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]documentationImprovements or additions to documentation. Applied to PRs that modify *.md files.enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions