Sign inSign up

docker/sbx-kit-panw-siem-telemetry:latest

Multi-platform
Manifest digest

sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e

yaml
schemaVersion: "3"
displayName: PANW SIEM Telemetry Forwarder
description: Ships sandbox observability (process, network, file, and agent-activity logs) to a SIEM HTTP event collector for dashboards, correlation, and automated response. Closes the visibility gap for what runs inside the sandbox.
sourceUrl: https://github.com/docker/sbx-kits-contrib/tree/main/panw-siem-telemetry
version: 1.0.0
licenses:
    - Apache-2.0
kind: mixin
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        install:
            allow:
                - raw.githubusercontent.com
                - packages.fluentbit.io
                - github.com
                - codeload.github.com
                - archive.ubuntu.com
                - security.ubuntu.com
                - ports.ubuntu.com
                - download.docker.com
        runtime:
            allow:
                - ${{ kit.args.siemCollectorHost }}
    - type: com.docker.sandbox/lifecycle@1
      config:
        files:
            - content: |
                #!/bin/sh
                # Launch the Fluent Bit telemetry forwarder with auth headers built at runtime.
                set -eu

                CONF_DIR=/home/agent/.config/fluent-bit
                BASE="$CONF_DIR/sandbox-telemetry.conf"
                RT=/home/agent/.sandbox/telemetry-runtime.conf

                mkdir -p /home/agent/.sandbox/logs
                cp "$BASE" "$RT"

                if [ -n "${SIEM_COLLECTOR_TOKEN:-}" ]; then
                    printf '    Header Authorization ${SIEM_COLLECTOR_TOKEN}\n' >> "$RT"
                fi

                AUTH_ID='${{ kit.args.siemCollectorAuthId }}'
                if [ -n "$AUTH_ID" ]; then
                    printf '    Header x-xdr-auth-id %s\n' "$AUTH_ID" >> "$RT"
                fi

                FLB="$(command -v fluent-bit || echo /opt/fluent-bit/bin/fluent-bit)"
                exec "$FLB" -c "$RT"
              mode: "0755"
              path: /home/agent/.config/fluent-bit/run-telemetry.sh
            - content: |
                [SERVICE]
                    Flush            5
                    Daemon           Off
                    Log_Level        info
                    Storage.path     /home/agent/.sandbox/telemetry-buffer
                    Storage.max_chunks_up 128
                    Parsers_File     /home/agent/.config/fluent-bit/parsers.conf

                [INPUT]
                    Name             tail
                    Path             /var/log/sandbox/*.log,/home/agent/.sandbox/logs/*.log
                    Tag              sandbox.activity
                    Refresh_Interval 5
                    Skip_Long_Lines  On
                    Storage.type     filesystem
                    Parser           json

                [FILTER]
                    Name             record_modifier
                    Match            *
                    Record           source docker-sandbox
                    Record           sandbox_host ${HOSTNAME}

                [OUTPUT]
                    Name             http
                    Match            *
                    Host             ${{ kit.args.siemCollectorHost }}
                    Port             443
                    URI              ${{ kit.args.siemCollectorPath }}
                    TLS              On
                    Format           json_lines
                    allow_duplicated_headers false
                    Header Content-Type application/json
                    Json_Date_Key    timestamp
                    Json_Date_Format iso8601
                    Retry_Limit      5
              mode: "0644"
              path: /home/agent/.config/fluent-bit/sandbox-telemetry.conf
        install:
            - command: mkdir -p /var/log/sandbox && chmod 0755 /var/log/sandbox
              description: Ensure the host-side sandbox log directory exists for the forwarder to tail
            - command: if command -v fluent-bit >/dev/null 2>&1 || [ -x /opt/fluent-bit/bin/fluent-bit ]; then exit 0; fi; if [ "$(getconf PAGESIZE)" = "4096" ]; then curl -fsSL https://raw.githubusercontent.com/fluent/fluent-bit/master/install.sh | sh || true; /opt/fluent-bit/bin/fluent-bit --version >/dev/null 2>&1 && exit 0; fi; set -e; apt-get update -qq; DEBIAN_FRONTEND=noninteractive apt-get install -y -qq build-essential cmake flex bison libssl-dev libyaml-dev pkg-config ca-certificates curl; curl -fsSL https://github.com/fluent/fluent-bit/archive/refs/tags/v5.1.2.tar.gz -o /tmp/fluent-bit-src.tar.gz; mkdir -p /tmp/fluent-bit-src; tar xzf /tmp/fluent-bit-src.tar.gz -C /tmp/fluent-bit-src --strip-components=1; cmake -S /tmp/fluent-bit-src -B /tmp/fluent-bit-build -DFLB_JEMALLOC=Off -DFLB_RELEASE=On -DFLB_EXAMPLES=Off -DFLB_TESTS_INTERNAL=Off -DFLB_TESTS_RUNTIME=Off -DCMAKE_INSTALL_PREFIX=/opt/fluent-bit; cmake --build /tmp/fluent-bit-build -j"$(nproc)"; cmake --install /tmp/fluent-bit-build; rm -rf /tmp/fluent-bit-src /tmp/fluent-bit-src.tar.gz /tmp/fluent-bit-build
              description: Install Fluent Bit - prebuilt on 4KB-page hosts, source build (jemalloc off) on 16KB-page hosts
              env:
                - HTTP_PROXY
                - HTTPS_PROXY
                - NO_PROXY
        startup:
            - background: true
              command:
                - sh
                - /home/agent/.config/fluent-bit/run-telemetry.sh
              description: Forward sandbox telemetry to the SIEM collector
              env:
                - SIEM_COLLECTOR_TOKEN
                - HTTP_PROXY
                - HTTPS_PROXY
                - NO_PROXY
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/panw-siem-telemetry/panw-siem-telemetry-context.md
args:
    siemCollectorAuthId:
        default: ""
        description: Cortex XSIAM HTTP Collector API key ID (numeric, non-secret), sent as the x-xdr-auth-id header alongside the Authorization token. XSIAM requires both; leave empty for collectors that authenticate with the Authorization header alone.
        pattern: ^[0-9]*$
    siemCollectorHost:
        default: siem-collector.example.com
        description: SIEM HTTP event collector ingestion host (FQDN, no scheme). Defaults to a placeholder; set it to your collector or telemetry has nowhere to ship.
        pattern: ^[a-z0-9]([a-z0-9.-]{0,251}[a-z0-9])?$
    siemCollectorPath:
        default: /logs/v1/event
        description: HTTP path on the collector to POST events to.
        pattern: ^/[A-Za-z0-9._~/-]*$