Skip to content

Commit 9110393

Browse files
google_scc: Add support for Security Command Center API v2 and update finding data stream to support Cloud Detection and Response (CDR) workflow
Some fields inside "google_scc.finding.resource" are moved into "google_scc.finding.resource.gcp_metadata" as per v2 API schema. This change allows to choose between v1 and v2 (recommended) APIs to fetch findings. Location-based findings can be fetched to support Security Command Center data residency feature. Field "google_scc.finding.vulnerability.cve.cvssv3.base_score" data type is updated to "double" to better suit data. In dashboards, ECS fields are used in preference to custom fields. Added "do_not_log_failure: true" to the asset and source data streams to prevent logging of expected pagination end failures, which have been causing system test failures from version 8.19 onwards. This issue arose due to the addition of Fleet health status updates in the httpjson input. Add ECS mappings and latest transform to finding data stream to help with the Cloud Native Vulnerability Management (CNVM)[1] and Cloud Security Posture Management (CSPM)[2] workflow. [1] https://www.elastic.co/guide/en/security/current/vuln-management-overview.html [2] https://www.elastic.co/docs/solutions/security/cloud/cloud-security-posture-management
1 parent 81fb067 commit 9110393

61 files changed

Lines changed: 9532 additions & 2046 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

packages/google_scc/_dev/build/docs/README.md

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,27 @@ If installing in GCP-Cloud Environment, No need to provide any credentials and m
8989
- topic
9090
- subscription name
9191

92+
## Troubleshooting
93+
94+
### Breaking Changes
95+
96+
#### Support for Elastic Vulnerability & Misconfiguration Findings page.
97+
98+
Version `2.0.0` of the Google Security Command Center integration adds support for [Elastic Cloud Security workflow](https://www.elastic.co/docs/solutions/security/cloud/ingest-third-party-cloud-security-data#_ingest_third_party_security_posture_and_vulnerability_data). The enhancement enables the users of Google Security Command Center integration to ingest vulnerabilities and misconfiguration findings from Google Security Command Center platform into Elastic and get insights directly from [Vulnerability Findings page](https://www.elastic.co/docs/solutions/security/cloud/findings-page-3) and [Misconfiguration Findings page](https://www.elastic.co/docs/solutions/security/cloud/findings-page).
99+
Version `2.0.0` adds [Elastic Latest Transform](https://www.elastic.co/docs/explore-analyze/transforms/transform-overview#latest-transform-overview) which copies the latest findings from source indices matching the pattern `logs-google_scc.finding-*` into new destination indices matching the pattern `security_solution-google_scc.vulnerability_latest-*` and `security_solution-google_scc.misconfiguration_latest-`. The Elastic Findings pages will display findings based on the destination indices.
100+
101+
For existing users of Google Security Command Center integration, before upgrading to version `2.0.0` please ensure following requirements are met:
102+
103+
1. Users need [Elastic Security solution](https://www.elastic.co/docs/solutions/security) which has requirements documented [here](https://www.elastic.co/docs/solutions/security/get-started/elastic-security-requirements).
104+
2. To use transforms, users must have:
105+
- at least one [transform node](https://www.elastic.co/docs/deploy-manage/distributed-architecture/clusters-nodes-shards/node-roles#transform-node-role),
106+
- management features visible in the Kibana space, and
107+
- security privileges that:
108+
- grant use of transforms, and
109+
- grant access to source and destination indices
110+
For more details on Transform Setup, refer to the link [here](https://www.elastic.co/docs/explore-analyze/transforms/transform-setup)
111+
3. Because the latest copy of findings is now indexed in two places, that is, in both source and destination indices, users must anticipate storage requirements accordingly.
112+
92113
## Logs reference
93114

94115
### Asset

packages/google_scc/_dev/deploy/docker/files/config.yml

Lines changed: 887 additions & 12 deletions
Large diffs are not rendered by default.
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
11
{"finding":{"name":"organizations/515665165161/sources/98481484454154454545/findings/414rfrhjebhrbhjbr444454hv54545","parent":"organizations/515665165161/sources/98481484454154454545","resourceName":"//cloudresourcemanager.googleapis.com/projects/45455445554","state":"ACTIVE","category":"application","externalUri":"http://www.adwait.com","sourceProperties":{},"securityMarks":{"name":"organizations/515665165161/sources/98481484454154454545/findings/414rfrhjebhrbhjbr444454hv54545/securityMarks"},"eventTime":"2023-06-02T05:17:41.936Z","createTime":"2020-02-19T13:37:43.858Z","severity":"CRITICAL","canonicalName":"organizations/515665165161/sources/98481484454154454545/findings/414rfrhjebhrbhjbr444454hv54545","mute":"UNMUTED","muteUpdateTime":"2022-03-23T05:50:21.804Z","externalSystems":{"test":{"name":"organizations/515665165161/sources/98481484454154454545/findings/414rfrhjebhrbhjbr444454hv54545/externalSystems/test","assignees":["primary"],"externalUid":"test_scc_finding_2","status":"updated1","externalSystemUpdateTime":"2022-01-05T05:00:35.674Z"}},"muteInitiator":"Unmuted by john@gmail.com"},"resource":{"name":"//cloudresourcemanager.googleapis.com/projects/45455445554"}}
2+
{"finding":{"canonicalName":"projects/101234567893/sources/01234567899876543210/locations/global/findings/452f80114abcdef0123456789abcdefd","category":"SOFTWARE_VULNERABILITY","contacts":{"security":{"contacts":[{"email":"security@example.com"}]}},"createTime":"2025-06-28T16:56:07.323Z","description":"Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.","eventTime":"2025-06-30T06:22:44.440Z","findingClass":"VULNERABILITY","mute":"UNDEFINED","muteUpdateTime":"1970-01-01T00:00:00Z","name":"organizations/901234567899/sources/01234567899876543210/locations/global/findings/452f80114abcdef0123456789abcdefd","parent":"organizations/901234567899/sources/01234567899876543210/locations/global","parentDisplayName":"Vulnerability Assessment","resourceName":"//compute.googleapis.com/projects/elastic-siem/zones/us-central1-c/instances/xyz-abcd-1234-abc-12-123","securityMarks":{"name":"organizations/901234567899/sources/01234567899876543210/locations/global/findings/452f80114abcdef0123456789abcdefd/securityMarks"},"severity":"HIGH","state":"ACTIVE","vulnerability":{"cve":{"cvssv3":{"attackComplexity":"ATTACK_COMPLEXITY_LOW","attackVector":"ATTACK_VECTOR_NETWORK","availabilityImpact":"IMPACT_HIGH","baseScore":7.5,"confidentialityImpact":"IMPACT_NONE","integrityImpact":"IMPACT_NONE","privilegesRequired":"PRIVILEGES_REQUIRED_NONE","scope":"SCOPE_UNCHANGED","userInteraction":"USER_INTERACTION_NONE"},"exploitReleaseDate":"1970-01-01T00:00:00Z","exploitationActivity":"NO_KNOWN","firstExploitationDate":"1970-01-01T00:00:00Z","id":"CVE-2023-24537","impact":"LOW","references":[{"source":"More Info","uri":"https://security-tracker.debian.org/tracker/CVE-2023-24537"},{"source":"More Info","uri":"https://access.redhat.com/security/cve/CVE-2023-24537"},{"source":"More Info","uri":"http://people.ubuntu.com/~ubuntu-security/cve/CVE-2023-24537"}],"upstreamFixAvailable":true},"fixedPackage":{"cpeUri":"cpe:/o:nvd:nvd:1.1","packageName":"go","packageType":"GO_STDLIB","packageVersion":"1.19.8"},"offendingPackage":{"cpeUri":"cpe:/o:nvd:nvd:1.1","packageName":"go","packageType":"GO_STDLIB","packageVersion":"1.13.8"},"securityBulletin":{"submissionTime":"1970-01-01T00:00:00Z"}}},"resource":{"cloudProvider":"GOOGLE_CLOUD_PLATFORM","displayName":"abc-wxyz-abcd-pqr-12-123","gcpMetadata":{"folders":[{"resourceFolder":"//cloudresourcemanager.googleapis.com/folders/801234567893","resourceFolderDisplayName":"Security"},{"resourceFolder":"//cloudresourcemanager.googleapis.com/folders/901234567891","resourceFolderDisplayName":"Engineering"},{"resourceFolder":"//cloudresourcemanager.googleapis.com/folders/901234567891","resourceFolderDisplayName":"Research and Development"}],"organization":"organizations/901234567899","parent":"//cloudresourcemanager.googleapis.com/projects/101234567893","parentDisplayName":"elastic-siem","project":"//cloudresourcemanager.googleapis.com/projects/101234567893","projectDisplayName":"elastic-siem"},"location":"us-central1-c","name":"//compute.googleapis.com/projects/elastic-siem/zones/us-central1-c/instances/abc-wxyz-abcd-pqr-12-123","resourcePath":{"nodes":[{"displayName":"elastic-siem","id":"projects/101234567893","nodeType":"GCP_PROJECT"},{"displayName":"Security","id":"folders/801234567893","nodeType":"GCP_FOLDER"},{"displayName":"Engineering","id":"folders/901234567891","nodeType":"GCP_FOLDER"},{"displayName":"Research and Development","id":"folders/901234567891","nodeType":"GCP_FOLDER"},{"id":"organizations/901234567899","nodeType":"GCP_ORGANIZATION"}]},"resourcePathString":"organizations/901234567899/folders/901234567891/folders/901234567891/folders/801234567893/projects/101234567893","service":"compute.googleapis.com","type":"google.compute.Instance"}}
3+
{"finding":{"canonicalName":"projects/101235645003/sources/14012345677654321025/locations/global/findings/9eaabcdef01234567890123456789147","category":"COMPUTE_SECURE_BOOT_DISABLED","contacts":{"security":{"contacts":[{"email":"security@example.com"}]}},"createTime":"2025-06-04T07:56:02.904Z","description":"Using secure boot helps protect your virtual machines against rootkits, boot- and kernel-level malware. Learn more at: https://cloud.google.com/security/shielded-cloud/shielded-vm","eventTime":"2025-06-04T07:44:08.656Z","externalUri":"https://console.cloud.google.com/compute/instancesDetail/zones/us-central1-b/instances/instance-20250528-112341?project=test-siem","findingClass":"MISCONFIGURATION","mute":"UNDEFINED","muteInfo":{"staticMute":{"applyTime":"1970-01-01T00:00:00Z","state":"UNDEFINED"}},"muteUpdateTime":"1970-01-01T00:00:00Z","name":"organizations/012345601234/sources/14012345677654321025/locations/global/findings/9eaabcdef01234567890123456789147","parent":"organizations/012345601234/sources/14012345677654321025/locations/global","parentDisplayName":"Security Health Analytics","resourceName":"//compute.googleapis.com/projects/test-siem/zones/us-central1-b/instances/instance-20250528-112341","securityMarks":{"name":"organizations/012345601234/sources/14012345677654321025/locations/global/findings/9eaabcdef01234567890123456789147/securityMarks"},"severity":"MEDIUM","sourceProperties":{"ExceptionInstructions":"Add the security mark \"allow_compute_secure_boot_disabled\" to the asset with a value of \"true\" to prevent this finding from being activated again.","Explanation":"Using secure boot helps protect your virtual machines against rootkits, boot- and kernel-level malware. Learn more at: https://cloud.google.com/security/shielded-cloud/shielded-vm","ReactivationCount":0,"Recommendation":"Go to https://console.cloud.google.com/compute/instancesDetail/zones/us-central1-b/instances/instance-20250528-112341?project=test-siem and click \"Stop\". Once the instance has stopped, scroll down to the \"Shielded VM\" section and check the \"Turn on Secure Boot\" checkbox. Then you can start the instance back up by clicking the \"Start\" button.","ResourcePath":["projects/test-siem/","folders/801234567893/","folders/901234567891/","folders/901234567890/","organizations/012345601234/"],"ScannerName":"COMPUTE_INSTANCE_SCANNER"},"state":"ACTIVE"},"resource":{"cloudProvider":"GOOGLE_CLOUD_PLATFORM","displayName":"instance-20250528-112341","gcpMetadata":{"folders":[{"resourceFolder":"//cloudresourcemanager.googleapis.com/folders/801234567893","resourceFolderDisplayName":"Security"},{"resourceFolder":"//cloudresourcemanager.googleapis.com/folders/901234567891","resourceFolderDisplayName":"Engineering"},{"resourceFolder":"//cloudresourcemanager.googleapis.com/folders/901234567890","resourceFolderDisplayName":"Research and Development"}],"organization":"organizations/012345601234","parent":"//cloudresourcemanager.googleapis.com/projects/101235645003","parentDisplayName":"test-siem","project":"//cloudresourcemanager.googleapis.com/projects/101235645003","projectDisplayName":"test-siem"},"location":"us-central1-b","name":"//compute.googleapis.com/projects/test-siem/zones/us-central1-b/instances/instance-20250528-112341","resourcePath":{"nodes":[{"displayName":"test-siem","id":"projects/101235645003","nodeType":"GCP_PROJECT"},{"displayName":"Security","id":"folders/801234567893","nodeType":"GCP_FOLDER"},{"displayName":"Engineering","id":"folders/901234567891","nodeType":"GCP_FOLDER"},{"displayName":"Research and Development","id":"folders/901234567890","nodeType":"GCP_FOLDER"},{"id":"organizations/012345601234","nodeType":"GCP_ORGANIZATION"}]},"resourcePathString":"organizations/012345601234/folders/901234567890/folders/901234567891/folders/801234567893/projects/101235645003","service":"compute.googleapis.com","type":"google.compute.Instance"}}

packages/google_scc/changelog.yml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,15 @@
11
# newer versions go on top
2+
- version: "2.0.0"
3+
changes:
4+
- description: |
5+
Add support for Findings v2 API. Parse and convert camelCase fields into snake_case fields.
6+
Some fields inside "google_scc.finding.resource" are moved into "google_scc.finding.resource.gcp_metadata" as per v2 API schema.
7+
This change allows to choose between v1 and v2 (recommended) APIs to fetch findings.
8+
Location-based findings can be fetched to support Security Command Center data residency feature.
9+
Field "google_scc.finding.vulnerability.cve.cvssv3.base_score" data type is updated to "float" to better suit data.
10+
Add mapping changes in `finding` datastream for Cloud Detection and Response (CDR) vulnerability and misconfiguration workflow.
11+
type: breaking-change
12+
link: https://github.com/elastic/integrations/pull/14629
213
- version: "1.10.1"
314
changes:
415
- description: Add temporary processor to remove the fields added by the Agentless policy.

packages/google_scc/data_stream/asset/_dev/test/pipeline/test-asset.log-expected.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -681,4 +681,4 @@
681681
},
682682
null
683683
]
684-
}
684+
}

packages/google_scc/data_stream/asset/_dev/test/system/test-default-config.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,7 @@
11
input: httpjson
2+
skip:
3+
reason: "The fleet health status changes to degraded when the HTTPJSON template's value evaluation comes up empty, which leads to system test failures but does not interrupt the data flow."
4+
link: https://github.com/elastic/beats/issues/45664
25
service: google_scc
36
vars:
47
credentials_type: credentials_json

packages/google_scc/data_stream/asset/agent/stream/httpjson.yml.hbs

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,12 +33,14 @@ request.transforms:
3333
response.pagination:
3434
- set:
3535
target: url.params.readTime
36-
value: '[[formatDate (parseDate .last_response.body.readTime) "RFC3339"]]'
36+
value: '[[if index .last_response.body "readTime"]][[formatDate (parseDate .last_response.body.readTime) "RFC3339"]][[end]]'
3737
fail_on_template_error: true
38+
do_not_log_failure: true
3839
- set:
3940
target: url.params.pageToken
4041
value: '[[if index .last_response.body "nextPageToken"]][[.last_response.body.nextPageToken]][[end]]'
4142
fail_on_template_error: true
43+
do_not_log_failure: true
4244
response.split:
4345
target: body.assets
4446
ignore_empty_value: true
Lines changed: 27 additions & 58 deletions
Original file line numberDiff line numberDiff line change
@@ -1,108 +1,77 @@
11
{
2-
"@timestamp": "2023-07-03T06:24:10.638Z",
2+
"@timestamp": "2025-07-30T10:45:24.425Z",
33
"agent": {
4-
"ephemeral_id": "7ab58b6a-e33a-470d-b529-80d7f867ce64",
5-
"id": "4c00a899-0103-47cf-a91d-fa52a48711c8",
6-
"name": "docker-fleet-agent",
4+
"ephemeral_id": "f9c21eae-c360-427b-afdf-3662d2d99c30",
5+
"id": "89379132-64b3-4465-ae5e-8d179096ac1b",
6+
"name": "elastic-agent-69527",
77
"type": "filebeat",
8-
"version": "8.8.0"
8+
"version": "8.19.0"
99
},
1010
"data_stream": {
1111
"dataset": "google_scc.asset",
12-
"namespace": "ep",
12+
"namespace": "56937",
1313
"type": "logs"
1414
},
1515
"ecs": {
1616
"version": "8.11.0"
1717
},
1818
"elastic_agent": {
19-
"id": "4c00a899-0103-47cf-a91d-fa52a48711c8",
20-
"snapshot": false,
21-
"version": "8.8.0"
19+
"id": "89379132-64b3-4465-ae5e-8d179096ac1b",
20+
"snapshot": true,
21+
"version": "8.19.0"
2222
},
2323
"event": {
2424
"agent_id_status": "verified",
2525
"category": [
2626
"host"
2727
],
28-
"created": "2023-07-03T06:24:26.934Z",
28+
"created": "2025-07-30T10:45:24.425Z",
2929
"dataset": "google_scc.asset",
30-
"id": "f14c38ac40-2",
31-
"ingested": "2023-07-03T06:24:30Z",
30+
"ingested": "2025-07-30T10:45:27Z",
3231
"kind": "event",
32+
"original": "{\"ancestors\":[\"organizations/523456987520\"],\"assetType\":\"cloudbilling.googleapis.com/BillingAccount\",\"name\":\"//cloudbilling.googleapis.com/billingAccounts/012345-A08098-1Ab2CD\",\"resource\":{\"data\":{\"displayName\":\"New\",\"name\":\"billingAccounts/012345-A08098-1Ab2CD\"},\"discoveryDocumentUri\":\"https://cloudbilling.googleapis.com/$discovery/rest\",\"discoveryName\":\"BillingAccount\",\"location\":\"global\",\"version\":\"v1\"},\"updateTime\":\"2022-11-17T12:20:17.601902Z\"}",
3333
"type": [
3434
"info"
3535
]
3636
},
3737
"google_scc": {
3838
"asset": {
3939
"ancestors": [
40-
"projects/123456987522",
41-
"folders/123456987520",
4240
"organizations/523456987520"
4341
],
44-
"prior": {
45-
"ancestors": [
46-
"projects/123456987522",
47-
"folders/123456987520",
48-
"organizations/523456987520"
49-
],
50-
"name": "//logging.googleapis.com/projects/123456987522/locations/global/buckets/_Default",
51-
"resource": {
52-
"data": {
53-
"analyticsEnabled": true,
54-
"description": "Default bucket",
55-
"lifecycleState": "ACTIVE",
56-
"name": "projects/123456987522/locations/global/buckets/_Default",
57-
"retentionDays": 30
58-
},
59-
"discovery": {
60-
"document_uri": "https://logging.googleapis.com/$discovery/rest",
61-
"name": "LogBucket"
62-
},
63-
"location": "global",
64-
"parent": "//cloudresourcemanager.googleapis.com/projects/123456987522",
65-
"version": "v2"
66-
},
67-
"type": "logging.googleapis.com/LogBucket",
68-
"update_time": "2023-05-27T18:53:48.843Z"
69-
},
70-
"prior_asset_state": "PRESENT",
42+
"name": "//cloudbilling.googleapis.com/billingAccounts/012345-A08098-1Ab2CD",
7143
"resource": {
7244
"data": {
73-
"description": "Default bucket",
74-
"lifecycleState": "ACTIVE",
75-
"name": "projects/123456987522/locations/global/buckets/_Default",
76-
"retentionDays": 30
45+
"displayName": "New",
46+
"name": "billingAccounts/012345-A08098-1Ab2CD"
7747
},
7848
"discovery": {
79-
"document_uri": "https://logging.googleapis.com/$discovery/rest",
80-
"name": "LogBucket"
49+
"document_uri": "https://cloudbilling.googleapis.com/$discovery/rest",
50+
"name": "BillingAccount"
8151
},
8252
"location": "global",
83-
"parent": "//cloudresourcemanager.googleapis.com/projects/123456987522",
84-
"version": "v2"
53+
"version": "v1"
8554
},
86-
"update_time": "2023-05-28T06:59:48.052Z",
87-
"window": {
88-
"start_time": "2023-05-28T06:59:48.052Z"
89-
}
55+
"type": "cloudbilling.googleapis.com/BillingAccount",
56+
"update_time": "2022-11-17T12:20:17.601Z"
9057
}
9158
},
9259
"host": {
93-
"name": "//logging.googleapis.com/projects/123456987522/locations/global/buckets/_Default",
94-
"type": "logging.googleapis.com/LogBucket"
60+
"name": "//cloudbilling.googleapis.com/billingAccounts/012345-A08098-1Ab2CD",
61+
"type": "cloudbilling.googleapis.com/BillingAccount"
9562
},
9663
"input": {
97-
"type": "gcp-pubsub"
64+
"type": "httpjson"
9865
},
9966
"related": {
10067
"hosts": [
101-
"//logging.googleapis.com/projects/123456987522/locations/global/buckets/_Default"
68+
"//cloudbilling.googleapis.com/billingAccounts/012345-A08098-1Ab2CD"
10269
]
10370
},
10471
"tags": [
72+
"preserve_original_event",
73+
"preserve_duplicate_custom_fields",
10574
"forwarded",
10675
"google_scc-asset"
10776
]
108-
}
77+
}

packages/google_scc/data_stream/audit/_dev/test/pipeline/test-audit.log-expected.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -76,4 +76,4 @@
7676
]
7777
}
7878
]
79-
}
79+
}

0 commit comments

Comments
 (0)