-
Notifications
You must be signed in to change notification settings - Fork 1.5k
DDS: Beyondtrust Privileged Remote Access v1.0.0 #22381
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
DDS: Beyondtrust Privileged Remote Access v1.0.0 #22381
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3e70457c35
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
beyondtrust_privileged_remote_access/assets/logs/beyondtrust-privileged-remote-access.yaml
Show resolved
Hide resolved
| "id": 2063743201609514, | ||
| "definition": { | ||
| "type": "note", | ||
| "content": "This dashboard provide comprehensive insights into authentication successes/failures, user identity modifications, admin resets, and credential enrollment/removal events. Designed to help security teams identify risky access patterns, account misuse, and compromised credentials.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "content": "This dashboard provide comprehensive insights into authentication successes/failures, user identity modifications, admin resets, and credential enrollment/removal events. Designed to help security teams identify risky access patterns, account misuse, and compromised credentials.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", | |
| "content": "This dashboard provides comprehensive insights into authentication successes/failures, user identity modifications, admin resets, and credential enrollment/removal events. It's designed to help security teams identify risky access patterns, account misuse, and compromised credentials.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| @@ -0,0 +1,3922 @@ | |||
| { | |||
| "title": "BeyondTrust PRA Authentication and Access Management", | |||
| "description": "This dashboard provide comprehensive insights into authentication successes/failures, user identity modifications, admin resets, and credential enrollment/removal events. Designed to help security teams identify risky access patterns, account misuse, and compromised credentials.", | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "description": "This dashboard provide comprehensive insights into authentication successes/failures, user identity modifications, admin resets, and credential enrollment/removal events. Designed to help security teams identify risky access patterns, account misuse, and compromised credentials.", | |
| "description": "This dashboard provides comprehensive insights into authentication successes/failures, user identity modifications, admin resets, and credential enrollment/removal events. It's designed to help security teams identify risky access patterns, account misuse, and compromised credentials.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| @@ -0,0 +1,3841 @@ | |||
| { | |||
| "title": "BeyondTrust PRA Identity and User Activity", | |||
| "description": "This dashboard provide comprehensive insights into how users access and interact with privileged systems. It highlights account changes, access configuration updates, and reporting actions to help security teams spot unusual behavior.", | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "description": "This dashboard provide comprehensive insights into how users access and interact with privileged systems. It highlights account changes, access configuration updates, and reporting actions to help security teams spot unusual behavior.", | |
| "description": "This dashboard provides comprehensive insights into how users access and interact with privileged systems. It highlights account changes, access configuration updates, and reporting actions to help security teams spot unusual behavior.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| "id": 120141214903234, | ||
| "definition": { | ||
| "type": "note", | ||
| "content": "This dashboard provide comprehensive insights into how users access and interact with privileged systems. It highlights account changes, access configuration updates, and reporting actions to help security teams spot unusual behavior.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "content": "This dashboard provide comprehensive insights into how users access and interact with privileged systems. It highlights account changes, access configuration updates, and reporting actions to help security teams spot unusual behavior.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", | |
| "content": "This dashboard provides comprehensive insights into how users access and interact with privileged systems. It highlights account changes, access configuration updates, and reporting actions to help security teams spot unusual behavior.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| "id": 797702432985848, | ||
| "definition": { | ||
| "type": "note", | ||
| "content": "This dashboard provide comprehensive insights into configuration changes across network objects, routing, syslog destinations, SNMP settings, API accounts, and external security providers to support change management, audit trails, and drift detection.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "content": "This dashboard provide comprehensive insights into configuration changes across network objects, routing, syslog destinations, SNMP settings, API accounts, and external security providers to support change management, audit trails, and drift detection.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", | |
| "content": "This dashboard provides comprehensive insights into configuration changes across network objects, routing, syslog destinations, SNMP settings, API accounts, and external security providers to support change management, audit trails, and drift detection.\n\nFor more information, see the [BeyondTrust Privileged Remote Access Integration Documentation](https://docs.datadoghq.com/integrations/beyondtrust_privileged_remote_access/).\n\n**Tips**\n- Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify, and add widgets and visualizations.", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| { | ||
| "id": 6112640160888389, | ||
| "definition": { | ||
| "title": "Events details", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "title": "Events details", | |
| "title": "Event details", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| { | ||
| "id": 2805558255072441, | ||
| "definition": { | ||
| "title": "Top Hosts by network address action", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "title": "Top Hosts by network address action", | |
| "title": "Top hosts by network address action", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| "id": 5234904368995564, | ||
| "definition": { | ||
| "type": "note", | ||
| "content": "Datadog Cloud SIEM analyzes and correlates the **BeyondTrust Privileged Remote Access** logs to detect threats to your environment in real time. If you don't see signals please make sure you've enabled [Datadog Cloud SIEM](/security/overview).", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| "content": "Datadog Cloud SIEM analyzes and correlates the **BeyondTrust Privileged Remote Access** logs to detect threats to your environment in real time. If you don't see signals please make sure you've enabled [Datadog Cloud SIEM](/security/overview).", | |
| "content": "Datadog Cloud SIEM analyzes and correlates the **BeyondTrust Privileged Remote Access** logs to detect threats to your environment in real time. If you don't see any signals, make sure you've enabled [Datadog Cloud SIEM](/security/overview).", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
Review from estherk15 is dismissed. Related teams and files:
- documentation
- beyondtrust_privileged_remote_access/assets/dashboards/beyondtrust_pra_authentication_and_access_management.json
- beyondtrust_privileged_remote_access/assets/dashboards/beyondtrust_pra_identity_and_user_activity.json
- beyondtrust_privileged_remote_access/assets/dashboards/beyondtrust_pra_network_and_platform_security.json
- beyondtrust_privileged_remote_access/assets/dashboards/beyondtrust_pra_overview.json
- beyondtrust_privileged_remote_access/manifest.json
|
The following files, which will be shipped with the agent, were modified in this PR and You can ignore this if you are sure the changes in this PR do not require QA. Otherwise, consider removing the label. List of modified files that will be shipped with the agent |
Review from estherk15 is dismissed. Related teams and files:
- documentation
- beyondtrust_privileged_remote_access/README.md
What does this PR do?
This is a initial release PR of BeyondTrust Privileged Remote Access integration including all the required assets.
Integration Logo Sources: https://assets.beyondtrust.com/assets/images/products/icons/pra-icon.svg
Review checklist (to be filled by reviewers)
[ ] Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
[ ] Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
[ ] If you need to backport this PR to another branch, you can add the backport/ label to the PR and it will automatically open a backport PR once this one is merged