Skip to content

feat[#266]: New Kits - auditd/cloudtrail/guardduty#266

Merged
bronson-peto-gravwell merged 21 commits intogravwell:mainfrom
bronson-peto-gravwell:Auditd-AWS
Mar 20, 2026
Merged

feat[#266]: New Kits - auditd/cloudtrail/guardduty#266
bronson-peto-gravwell merged 21 commits intogravwell:mainfrom
bronson-peto-gravwell:Auditd-AWS

Conversation

@bronson-peto-gravwell
Copy link
Copy Markdown
Collaborator

@bronson-peto-gravwell bronson-peto-gravwell commented Mar 12, 2026

This PR addresses creation of 3 new kits

@kyle-mallett-gravwell
Copy link
Copy Markdown
Contributor

kyle-mallett-gravwell commented Mar 19, 2026

auditd/aws_cloudtrail/aws_guardduty

  1. Please update auditd kitName/ID to match Gravwell format
    io.gravwell.auditd

  2. Set MaxVersion to 5.99
    "MaxVersion": { "Major": 5, "Minor": 99, "Point": 0 },

  3. Remove ConfigMacros in MANIFEST if no macros present in macros/.
    auditd/MANIFEST
    aws_cloudtrail/MANIFEST

  4. Add macro/ back in since searchlibrary/ queries depend on the macro.

https://github.com/gravwell/kits/actions/runs/23268181682/job/67654280571

  • not sure if you cancelled this manually, or we need to look into 'build kitctl' process...but it did build and load into my local instance of Gravwell

Copy link
Copy Markdown
Contributor

@kyle-mallett-gravwell kyle-mallett-gravwell left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm; spoke with Bronson about ConfigMacros in MANIFEST, they were built regardless of being in macro/ since they were defined as a ConfigMacro.

@kyle-mallett-gravwell kyle-mallett-gravwell changed the title Adding new kits - auditd/cloudtrail/guardduty feat[#266]: New Kits - auditd/cloudtrail/guardduty Mar 19, 2026
@kyle-mallett-gravwell
Copy link
Copy Markdown
Contributor

@mike-wade-gravwell when you get the chance

Copy link
Copy Markdown
Contributor

@mike-wade-gravwell mike-wade-gravwell left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@bronson-peto-gravwell bronson-peto-gravwell merged commit 2ca8b93 into gravwell:main Mar 20, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants