Loading...
Loading...
Compare original and translation side by side
/create-integrationgeneralPurposegeneral-purposereferences/research-subagent-guidance.md/create-integrationgeneralPurposegeneral-purposereferences/research-subagent-guidance.md@| Input | How to provide | Examples |
|---|---|---|
| Product / vendor / feature | free text | "Checkpoint Harmony Endpoint", "Okta System Log", "AWS CloudTrail via S3" |
| Known collection method | free text (optional) | "REST API", "syslog", "S3/SQS", "Azure Event Hub" |
| Documentation URLs | paste URLs | |
| Local reference material | | |
| Scope constraints | free text | "only the alerts API", "focus on firewall logs", "audit events only" |
| Output name override | free text | "checkpoint_harmony" (defaults to sanitized product name) |
/research-integration@| 输入项 | 提供方式 | 示例 |
|---|---|---|
| 产品/供应商/功能 | 自由文本 | "Checkpoint Harmony Endpoint"、"Okta System Log"、"AWS CloudTrail via S3" |
| 已知收集方法 | 自由文本(可选) | "REST API"、"syslog"、"S3/SQS"、"Azure Event Hub" |
| 文档URL | 直接粘贴URL | |
| 本地参考资料 | | |
| 范围约束 | 自由文本 | "仅调研告警API"、"重点关注防火墙日志"、"仅审计事件" |
| 输出名称覆盖 | 自由文本 | "checkpoint_harmony"(默认值为经过清洗的产品名称) |
/research-integration/research-integration Checkpoint Harmony Endpoint security events
API docs: https://developer.checkpoint.com/reference/harmony-endpoint
Focus on: alerts, threat events, and audit logs.
Known method: REST API with pagination./research-integration Palo Alto Cortex XDR
@notes/cortex-xdr-api-rough-notes.md
Need to investigate both the Incidents API and Alerts API./research-integration Cisco Meraki syslog events
https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_and_Log_Samples
Focus on: firewall, URL, and IDS event types.
Known method: syslog over UDP/TCP./research-integration AWS Security Hub findings via S3/SQS
Need full schema of ASFF finding format and S3 delivery configuration./research-integration Checkpoint Harmony Endpoint安全事件
API文档:https://developer.checkpoint.com/reference/harmony-endpoint
重点关注:告警、威胁事件和审计日志。
已知方法:带分页的REST API。/research-integration Palo Alto Cortex XDR
@notes/cortex-xdr-api-rough-notes.md
需要同时调研Incidents API和Alerts API。/research-integration Cisco Meraki syslog事件
https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_and_Log_Samples
重点关注:防火墙、URL和IDS事件类型。
已知方法:基于UDP/TCP的syslog。/research-integration AWS Security Hub findings via S3/SQS
需要ASFF发现格式的完整schema以及S3交付配置信息。references/data-collection-methods.mdreferences/research-output-template.mdreferences/api-research-checklist.mdreferences/log-file-research-checklist.mdreferences/cloud-ingest-research-checklist.mdreferences/test-api-script-spec.mdecs-field-mappingsreferences/competitive-siem-coverage-checklist.mdreferences/research-subagent-guidance.mdreferences/data-collection-methods.mdreferences/research-output-template.mdreferences/api-research-checklist.mdreferences/log-file-research-checklist.mdreferences/cloud-ingest-research-checklist.mdreferences/test-api-script-spec.mdecs-field-mappingsreferences/competitive-siem-coverage-checklist.mdreferences/research-subagent-guidance.mdresearch_results/<product_slug>/<product_slug>checkpoint_harmony_endpointpalo_alto_cortex_xdrcisco_merakiresearch_results/<product_slug>/
research-brief.md # the main structured research brief
test-api.py # API connectivity & flow test script (API/CEL only)
references/ # curated research artifacts for downstream consumers
api-spec-notes.md # API endpoint details, request/response examples (if API)
log-format-notes.md # log format details, sample lines (if log-based)
field-schema-analysis.md # detailed field inventories written by subagents
competitive-siem-coverage.md # detailed competitive SIEM analysis (always created)
sample-events/ # representative sample data files
<event_type>.json # one file per event type or data format variant
<event_type>.log
temp/ # downloaded raw artifacts (repos, SDKs, schemas, scripts)
<descriptive-subfolder>/ # e.g., vendor-sdk/, schema-files/, openapi-spec/
ecs-mapping-analysis.md # initial ECS field mapping analysis
configuration-plan.md # planned integration configuration variablestemp/temp/research_results/<product_slug>/<product_slug>checkpoint_harmony_endpointpalo_alto_cortex_xdrcisco_merakiresearch_results/<product_slug>/
research-brief.md # 主结构化调研简报
test-api.py # API连通性与流程测试脚本(仅API/CEL类型)
references/ # 为下游使用者整理的调研工件
api-spec-notes.md # API端点详情、请求/响应示例(若为API类型)
log-format-notes.md # 日志格式详情、样本行(若为日志类型)
field-schema-analysis.md # 子Agent编写的详细字段清单
competitive-siem-coverage.md # 详细竞品SIEM分析(始终生成)
sample-events/ # 代表性样本数据文件
<event_type>.json # 每种事件类型或数据格式变体对应一个文件
<event_type>.log
temp/ # 下载的原始工件(仓库、SDK、schema、脚本)
<descriptive-subfolder>/ # 例如vendor-sdk/、schema-files/、openapi-spec/
ecs-mapping-analysis.md # 初始ECS字段映射分析
configuration-plan.md # 规划的集成配置变量temp/temp/@@@research_results/<product_slug>/temp/references/temp/references/temp/references/research-subagent-guidance.mdresearch-integrationtemp/Working directory: research_results/<product_slug>/
- Download raw artifacts to: research_results/<product_slug>/temp/
- Write curated findings to: research_results/<product_slug>/references/@@research_results/<product_slug>/temp/references/temp/references/temp/references/research-subagent-guidance.mdresearch-integrationtemp/工作目录:research_results/<product_slug>/
- 将原始工件下载至:research_results/<product_slug>/temp/
- 将整理后的发现写入:research_results/<product_slug>/references/@api-research-checklist.mdtemp/temp/api-research-checklist.mdtemp/temp/temp/references/field-schema-analysis.mdtemp/references/field-schema-analysis.mdreferences/competitive-siem-coverage-checklist.mdreferences/research-subagent-guidance.mdhttps://www.ibm.com/products/qradar-siem/integrationshttps://splunkbase.splunk.com/appshttps://www.sumologic.com/help/docs/integrations/references/competitive-siem-coverage.mdreferences/competitive-siem-coverage-checklist.mdreferences/competitive-siem-coverage-checklist.mdreferences/research-subagent-guidance.mdhttps://www.ibm.com/products/qradar-siem/integrationshttps://splunkbase.splunk.com/appshttps://www.sumologic.com/help/docs/integrations/references/competitive-siem-coverage.mdreferences/competitive-siem-coverage-checklist.mdreferences/temp/[UNVERIFIED]sample-events/temp/references/competitive-siem-coverage.mdreferences/temp/[UNVERIFIED]sample-events/temp/references/competitive-siem-coverage.mdevent.kindevent.categoryevent.typeevent.outcomerelated.iprelated.userrelated.hostsrelated.hashecs-mapping-analysis.mdevent.kindevent.categoryevent.typeevent.outcomerelated.iprelated.userrelated.hostsrelated.hashecs-mapping-analysis.mdreferences/data-collection-methods.mdconfiguration-plan.mdreferences/data-collection-methods.mdconfiguration-plan.mdreferences/research-output-template.mdresearch_results/<product_slug>/research-brief.md/create-integrationreferences/competitive-siem-coverage.mdSee references/competitive-siem-coverage.md for full per-vendor analysis.references/research-output-template.mdresearch_results/<product_slug>/research-brief.md/create-integrationreferences/competitive-siem-coverage.md详见references/competitive-siem-coverage.md获取完整的供应商分析。references/test-api-script-spec.mdconfiguration-plan.mdresearch_results/<product_slug>/test-api.pyurllib.requestjsonloggingargparsesslargparsedefault=os.environ.get(...)https://...--max-pagestest-api.logloggingtrace.json.tar.gzKeyboardInterruptreferences/test-api-script-spec.mdconfiguration-plan.mdresearch_results/<product_slug>/test-api.pyurllib.requestjsonloggingargparsesslargparsedefault=os.environ.get(...)https://...--max-pagestest-api.logloggingtrace.json.tar.gzKeyboardInterrupttest-api.pypython3 -m py_compile research_results/<product_slug>/test-api.pytest-api.py/create-integrationtest-api.pypython3 -m py_compile research_results/<product_slug>/test-api.pytest-api.py/create-integration[CONSTRUCTED EXAMPLE][UNVERIFIED]next_cursorcursor[CONSTRUCTED EXAMPLE][UNVERIFIED]next_cursorcursorrate_limit()next_cursormore_to_readmore_to_readwant_more: body.more_to_readstate.?cursor.next_cursorX-Ratelimit-LimitX-Ratelimit-RemainingX-Ratelimit-Resetrate_limit()fields/*.ymlmanifest.ymlingest-pipelinesecs-field-mappingspackage-specreview-integrationpreserve_duplicate_custom_fieldsingest-pipelines/SKILL.mdevent.ingestedevent.originalpreserve_duplicate_custom_fieldspreserve_*preserve_original_eventreferences/data-collection-methods.mdsrcipsource.ippreserve_duplicate_custom_fieldssrcipsource.ipdatetarget_field: event.start@timestampon_failurereferences/data-collection-methods.mdrate_limit()next_cursormore_to_readmore_to_readwant_more: body.more_to_readstate.?cursor.next_cursorX-Ratelimit-LimitX-Ratelimit-RemainingX-Ratelimit-Resetrate_limit()fields/*.ymlmanifest.ymlingest-pipelinesecs-field-mappingspackage-specreview-integrationpreserve_duplicate_custom_fieldsingest-pipelines/SKILL.mdevent.ingestedevent.originalpreserve_duplicate_custom_fieldspreserve_*preserve_original_eventreferences/data-collection-methods.mdsrcipsource.ippreserve_duplicate_custom_fieldssrcipsource.ipdatetarget_field: event.start@timestampreferences/data-collection-methods.mdtest-api.py.tar.gz/create-integration @research_results/<product_slug>/research-brief.mdresearch_results/<product_slug>/references/sample-events/@test-api.py.tar.gz/create-integration @research_results/<product_slug>/research-brief.md@research_results/<product_slug>/references/sample-events/