elastic / elastic/integrations

[File Integrity Monitoring]: Provide more specific actions

Open
#13,669 4 comments 0 reactions 0 assignees View on GitHub
Integration:fim needs:triage Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

File Integrity Monitoring [fim]

### Dataset Name

_No response_

### Integration Version

1.16.0

### Agent Version

8.18.0

### OS Version and Architecture

RHEL 9.3

### User Goal

I want to leverage Elastic's FIM but it could a bit basic. I am requesting that the details like (created/modified/deleted), but more granular like:
- File deleted
- File created
- File opened
- File modified
- Permissions added
- Folder created
- Permissions removed

### Existing Features

I think the current methods are alright, need to be expanded more.

### What did you see?

![Image](https://github.com/user-attachments/assets/f953f8cf-cdc5-4414-bc5f-798d3653b728)

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.