Skip to content

[SEC-36059] Add Anomali ThreatStream Account Config to Assets - #24892

Merged
seohyunh merged 2 commits into
masterfrom
seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets
Aug 24, 2026
Merged

[SEC-36059] Add Anomali ThreatStream Account Config to Assets#24892
seohyunh merged 2 commits into
masterfrom
seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets

Conversation

@seohyunh

@seohyunh seohyunh commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds the Anomali ThreatStream account_config.json asset used to generate the AMS account setup UI.

The schema defines the ThreatStream domain, email, API key, and default-enabled domain, IP address, and SHA256 indicator collection options. Its keys, labels, validation, defaults, and dataflow ID match the crawler-sdk configuration contract.

Motivation

Completes the AMS account configuration schema for the Anomali ThreatStream threat intelligence integration under SEC-36059.

This PR depends on:

This PR should remain draft until both dependencies are ready.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add qa/required if this PR needs QA validation, or qa/skip-qa if it does not. Exactly one of the two is required. (qa/skip-qa: this asset does not ship with the Datadog Agent.)
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@seohyunh seohyunh changed the title add anomali threatstream account config [SEC-36059] Add Anomali ThreatStream Account Config Aug 17, 2026
@datadog-datadog-prod-us1-2

This comment has been minimized.

@cit-pr-commenter-54b7da

cit-pr-commenter-54b7da Bot commented Aug 17, 2026

Copy link
Copy Markdown

evalya-impact-summary

evalya impact analysis
Impact analysis: RUN-ALL — every test task will run
Trigger:         empty diff (default branch, scheduled run, or shallow-clone fallback)
Test tasks:      0 (all selected)
Publish tasks:   1 (always emitted)
Diff:            empty (no diff information)

Learn more about CI impact filtering

@seohyunh
seohyunh force-pushed the seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets branch 2 times, most recently from 702fcb5 to bf55aff Compare August 18, 2026 14:55
@seohyunh seohyunh added the qa/skip-qa Automatically skip this PR for the next QA label Aug 18, 2026
@seohyunh
seohyunh marked this pull request as ready for review August 18, 2026 18:18
@seohyunh
seohyunh requested a review from a team as a code owner August 18, 2026 18:18

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

The added account schema’s fields and defaults align with repository conventions, and its dataflow ID resolves to the existing Anomali ThreatStream dataflow.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit bf55aff · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@seohyunh
seohyunh force-pushed the seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets branch 2 times, most recently from df32eb1 to 0c819bb Compare August 21, 2026 20:54
@seohyunh seohyunh changed the title [SEC-36059] Add Anomali ThreatStream Account Config [SEC-36059] Add Anomali ThreatStream Account Config to Assets Aug 21, 2026
@seohyunh
seohyunh force-pushed the seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets branch from 0c819bb to 594abd8 Compare August 24, 2026 13:31
@seohyunh
seohyunh marked this pull request as draft August 24, 2026 14:07
@seohyunh
seohyunh marked this pull request as ready for review August 24, 2026 14:07
@seohyunh
seohyunh requested a review from a team as a code owner August 24, 2026 14:07

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

The asset keeps the account field keys and dataflow ID consistent with the integration contract. No changed line creates a concrete failure mode.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit 594abd8 · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@dd-octo-sts

dd-octo-sts Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Validation Report

All 21 validations passed.

Show details
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
qa-label Validate the pull request declares whether it needs QA for the next Agent release
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

@seohyunh
seohyunh added this pull request to the merge queue Aug 24, 2026
Merged via the queue into master with commit 72cfddd Aug 24, 2026
57 checks passed
@seohyunh
seohyunh deleted the seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets branch August 24, 2026 21:07
@dd-octo-sts dd-octo-sts Bot added this to the 7.83.0 milestone Aug 24, 2026
github-actions Bot pushed a commit to ConnectionMaster/integrations-core that referenced this pull request Aug 25, 2026
…g#24892)

* add anomali threatstream account config

* ci: retrigger checks 72cfddd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants