Skip to content

[SEC-36059] Add Anomali ThreatStream Account Config - #24892

Open
seohyunh wants to merge 1 commit into
masterfrom
seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets
Open

[SEC-36059] Add Anomali ThreatStream Account Config#24892
seohyunh wants to merge 1 commit into
masterfrom
seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets

Conversation

@seohyunh

@seohyunh seohyunh commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds the Anomali ThreatStream account_config.json asset used to generate the AMS account setup UI.

The schema defines the ThreatStream domain, email, API key, and default-enabled domain, IP address, and SHA256 indicator collection options. Its keys, labels, validation, defaults, and dataflow ID match the crawler-sdk configuration contract.

Motivation

Completes the AMS account configuration schema for the Anomali ThreatStream threat intelligence integration under SEC-36059.

This PR depends on:

This PR should remain draft until both dependencies are ready.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add qa/required if this PR needs QA validation, or qa/skip-qa if it does not. Exactly one of the two is required. (qa/skip-qa: this asset does not ship with the Datadog Agent.)
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@seohyunh seohyunh changed the title add anomali threatstream account config [SEC-36059] Add Anomali ThreatStream Account Config Aug 17, 2026
@datadog-datadog-prod-us1-2

This comment has been minimized.

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

evalya-impact-summary

evalya impact analysis
Impact analysis: 0 selected, 0 skipped (of 0 test tasks)
Publish tasks:   1 (always emitted)
Diff (1 file):
  anomali_threatstream/assets/account_config.json

Debug a specific task: evalya plan impact --path <path> --task <task>

Learn more about CI impact filtering

@seohyunh
seohyunh force-pushed the seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets branch 2 times, most recently from 702fcb5 to bf55aff Compare August 18, 2026 14:55
@seohyunh seohyunh added the qa/skip-qa Automatically skip this PR for the next QA label Aug 18, 2026
@seohyunh
seohyunh marked this pull request as ready for review August 18, 2026 18:18
@seohyunh
seohyunh requested a review from a team as a code owner August 18, 2026 18:18

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

The added account schema’s fields and defaults align with repository conventions, and its dataflow ID resolves to the existing Anomali ThreatStream dataflow.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit bf55aff · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@seohyunh
seohyunh force-pushed the seohyun.hwang/SEC-36059-anomali-threatstream-account-config-assets branch from bf55aff to df32eb1 Compare August 18, 2026 20:15
@dd-octo-sts

dd-octo-sts Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Validation Report

All 21 validations passed.

Show details
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
qa-label Validate the pull request declares whether it needs QA for the next Agent release
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant