Skip to content

[DOCS] Fix links to the Filebeat Google Workspace module #1441

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jan 26, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when multi-factor authentication (MFA) enforcement is disabled for Googl
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information.
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Detects when a Google Workspace password policy is modified. An adversary may at
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -56,7 +56,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information.
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Detects when multi-factor authentication (MFA) is disabled for a Google Workspac
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -56,7 +56,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information.
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when a Google marketplace application is added to the Google Workspace d
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when a domain is added to the list of trusted Google Workspace domains.
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when an admin role is assigned to a Google Workspace user. An adversary
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when a custom admin role is deleted. An adversary may delete a custom ad
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when a domain-wide delegation of authority is granted to a service accou
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when a custom admin role is created in Google Workspace. An adversary ma
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when multi-factor authentication (MFA) enforcement is disabled for Googl
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Detects when a Google Workspace password policy is modified. An adversary may at
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -56,7 +56,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ Detects when a custom admin role or its permissions are modified. An adversary m
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -58,7 +58,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Detects when multi-factor authentication (MFA) is disabled for a Google Workspac
==== Investigation guide


[source, markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -56,7 +56,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------

==== Rule query
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Applications can be added to a Google Workspace domain by system administrators.
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Trusted domains may be added by system administrators. Verify that the configura
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Google Workspace admin role assignments may be modified by system administrators
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Google Workspace admin roles may be deleted by system administrators. Verify tha
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Domain-wide delegation of authority may be granted to service accounts by system
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Custom Google Workspace admin roles may be created by system administrators. Ver
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ MFA policies may be modified by system administrators. Verify that the configura
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ Password policies may be modified by system administrators. Verify that the conf
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -59,7 +59,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Google Workspace admin roles may be modified by system administrators. Verify th
==== Investigation guide


[source,markdown]
[source, markdown, subs="attributes"]
----------------------------------
## Config

Expand All @@ -63,7 +63,7 @@ The Google Workspace Fleet integration, Filebeat module, or similarly structured
- By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m).
- See the following references for further information:
- https://support.google.com/a/answer/7061566
- https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html
- https://www.elastic.co/guide/en/beats/filebeat/{branch}/filebeat-module-google_workspace.html
----------------------------------


Expand Down
Loading