-
Notifications
You must be signed in to change notification settings - Fork 502
microsoft_defender_endpoint: add support for oauth endpoint params #15667
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
chemamartinez
merged 4 commits into
elastic:main
from
chemamartinez:15605-mdefender-endpoint-oauth-endpoint-params
Oct 22, 2025
Merged
microsoft_defender_endpoint: add support for oauth endpoint params #15667
chemamartinez
merged 4 commits into
elastic:main
from
chemamartinez:15605-mdefender-endpoint-oauth-endpoint-params
Oct 22, 2025
+364
−151
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportPackage
|
| Data stream | Previous EPS | New EPS | Diff (%) | Result |
|---|---|---|---|---|
log |
3012.05 | 2525.25 | -486.8 (-16.16%) | 💔 |
To see the full report comment with /test benchmark fullreport
efd6
reviewed
Oct 20, 2025
packages/microsoft_defender_endpoint/data_stream/log/agent/stream/httpjson.yml.hbs
Show resolved
Hide resolved
💚 Build Succeeded
History
|
efd6
approved these changes
Oct 21, 2025
|
Package microsoft_defender_endpoint - 4.1.0 containing this change is available at https://epr.elastic.co/package/microsoft_defender_endpoint/4.1.0/ |
alexreal1314
pushed a commit
to alexreal1314/integrations
that referenced
this pull request
Oct 22, 2025
…lastic#15667) Add support for the oauth_endpoint_params configuration parameter for all available data streams. Log data stream still works under httpjson so the option has been added under data stream level along with all the OAuth2 options for this data stream. For the another data streams, as they work under the CEL input, it has been added at input level so adding any value to this option will affect all data streams that rely on CEL (machine, machine_action, and vulnerability). Finally, the auth logic for the vulnerability data stream is implemented in the CEL program instead of delegate in the CEL auth options for the input. Therefore, the oauth endpoint params in this case are added manually in the program as well.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
documentation
Improvements or additions to documentation. Applied to PRs that modify *.md files.
enhancement
New feature or request
Integration:microsoft_defender_endpoint
Microsoft Defender for Endpoint
Team:Security-Service Integrations
Security Service Integrations team [elastic/security-service-integrations]
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Proposed commit message
Add support for the
oauth_endpoint_paramsconfiguration parameter for all available data streams.Logdata stream still works under httpjson so the option has been added under data stream level along with all the OAuth2 options for this data stream.For the another data streams, as they work under the CEL input, it has been added at input level so adding any value to this option will affect all data streams that rely on CEL (
machine,machine_action, andvulnerability).Finally, the auth logic for the vulnerability data stream is implemented in the CEL program instead of delegate in the CEL auth options for the input. Therefore, the oauth endpoint params in this case are added manually in the program as well.
Checklist
changelog.ymlfile.Related issues
Screenshots