-
Notifications
You must be signed in to change notification settings - Fork 463
[system] Add support for more event-ids in the security data stream #13828
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
[system] Add support for more event-ids in the security data stream #13828
Conversation
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
Hi @jamiehynds ,@kcreddy , @efd6, |
💔 Build Failed
Failed CI StepsHistory
|
LGMT in general, just a couple of things:
|
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
Proposed commit message
This PR adds support for more event-ids of
Security Events
tosystem.security
. These events have an event.code as below:System fields are mapped to their corresponding ECS fields where possible. And also added associated dashboards and visualizations.
Test samples were derived from live logs and documentation and subsequently sanitized.
Checklist
How to test this PR locally
Related issues
Screenshot