sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e
schemaVersion: "3"
displayName: PANW SIEM Telemetry Forwarder
description: Ships sandbox observability (process, network, file, and agent-activity logs) to a SIEM HTTP event collector for dashboards, correlation, and automated response. Closes the visibility gap for what runs inside the sandbox.
sourceUrl: https://github.com/docker/sbx-kits-contrib/tree/main/panw-siem-telemetry
version: 1.0.0
licenses:
- Apache-2.0
kind: mixin
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
install:
allow:
- raw.githubusercontent.com
- packages.fluentbit.io
- github.com
- codeload.github.com
- archive.ubuntu.com
- security.ubuntu.com
- ports.ubuntu.com
- download.docker.com
runtime:
allow:
- ${{ kit.args.siemCollectorHost }}
- type: com.docker.sandbox/lifecycle@1
config:
files:
- content: |
#!/bin/sh
# Launch the Fluent Bit telemetry forwarder with auth headers built at runtime.
set -eu
CONF_DIR=/home/agent/.config/fluent-bit
BASE="$CONF_DIR/sandbox-telemetry.conf"
RT=/home/agent/.sandbox/telemetry-runtime.conf
mkdir -p /home/agent/.sandbox/logs
cp "$BASE" "$RT"
if [ -n "${SIEM_COLLECTOR_TOKEN:-}" ]; then
printf ' Header Authorization ${SIEM_COLLECTOR_TOKEN}\n' >> "$RT"
fi
AUTH_ID='${{ kit.args.siemCollectorAuthId }}'
if [ -n "$AUTH_ID" ]; then
printf ' Header x-xdr-auth-id %s\n' "$AUTH_ID" >> "$RT"
fi
FLB="$(command -v fluent-bit || echo /opt/fluent-bit/bin/fluent-bit)"
exec "$FLB" -c "$RT"
mode: "0755"
path: /home/agent/.config/fluent-bit/run-telemetry.sh
- content: |
[SERVICE]
Flush 5
Daemon Off
Log_Level info
Storage.path /home/agent/.sandbox/telemetry-buffer
Storage.max_chunks_up 128
Parsers_File /home/agent/.config/fluent-bit/parsers.conf
[INPUT]
Name tail
Path /var/log/sandbox/*.log,/home/agent/.sandbox/logs/*.log
Tag sandbox.activity
Refresh_Interval 5
Skip_Long_Lines On
Storage.type filesystem
Parser json
[FILTER]
Name record_modifier
Match *
Record source docker-sandbox
Record sandbox_host ${HOSTNAME}
[OUTPUT]
Name http
Match *
Host ${{ kit.args.siemCollectorHost }}
Port 443
URI ${{ kit.args.siemCollectorPath }}
TLS On
Format json_lines
allow_duplicated_headers false
Header Content-Type application/json
Json_Date_Key timestamp
Json_Date_Format iso8601
Retry_Limit 5
mode: "0644"
path: /home/agent/.config/fluent-bit/sandbox-telemetry.conf
install:
- command: mkdir -p /var/log/sandbox && chmod 0755 /var/log/sandbox
description: Ensure the host-side sandbox log directory exists for the forwarder to tail
- command: if command -v fluent-bit >/dev/null 2>&1 || [ -x /opt/fluent-bit/bin/fluent-bit ]; then exit 0; fi; if [ "$(getconf PAGESIZE)" = "4096" ]; then curl -fsSL https://raw.githubusercontent.com/fluent/fluent-bit/master/install.sh | sh || true; /opt/fluent-bit/bin/fluent-bit --version >/dev/null 2>&1 && exit 0; fi; set -e; apt-get update -qq; DEBIAN_FRONTEND=noninteractive apt-get install -y -qq build-essential cmake flex bison libssl-dev libyaml-dev pkg-config ca-certificates curl; curl -fsSL https://github.com/fluent/fluent-bit/archive/refs/tags/v5.1.2.tar.gz -o /tmp/fluent-bit-src.tar.gz; mkdir -p /tmp/fluent-bit-src; tar xzf /tmp/fluent-bit-src.tar.gz -C /tmp/fluent-bit-src --strip-components=1; cmake -S /tmp/fluent-bit-src -B /tmp/fluent-bit-build -DFLB_JEMALLOC=Off -DFLB_RELEASE=On -DFLB_EXAMPLES=Off -DFLB_TESTS_INTERNAL=Off -DFLB_TESTS_RUNTIME=Off -DCMAKE_INSTALL_PREFIX=/opt/fluent-bit; cmake --build /tmp/fluent-bit-build -j"$(nproc)"; cmake --install /tmp/fluent-bit-build; rm -rf /tmp/fluent-bit-src /tmp/fluent-bit-src.tar.gz /tmp/fluent-bit-build
description: Install Fluent Bit - prebuilt on 4KB-page hosts, source build (jemalloc off) on 16KB-page hosts
env:
- HTTP_PROXY
- HTTPS_PROXY
- NO_PROXY
startup:
- background: true
command:
- sh
- /home/agent/.config/fluent-bit/run-telemetry.sh
description: Forward sandbox telemetry to the SIEM collector
env:
- SIEM_COLLECTOR_TOKEN
- HTTP_PROXY
- HTTPS_PROXY
- NO_PROXY
user: "1000"
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/panw-siem-telemetry/panw-siem-telemetry-context.md
args:
siemCollectorAuthId:
default: ""
description: Cortex XSIAM HTTP Collector API key ID (numeric, non-secret), sent as the x-xdr-auth-id header alongside the Authorization token. XSIAM requires both; leave empty for collectors that authenticate with the Authorization header alone.
pattern: ^[0-9]*$
siemCollectorHost:
default: siem-collector.example.com
description: SIEM HTTP event collector ingestion host (FQDN, no scheme). Defaults to a placeholder; set it to your collector or telemetry has nowhere to ship.
pattern: ^[a-z0-9]([a-z0-9.-]{0,251}[a-z0-9])?$
siemCollectorPath:
default: /logs/v1/event
description: HTTP path on the collector to POST events to.
pattern: ^/[A-Za-z0-9._~/-]*$