-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Filebeat] Add source.as.organization.name to cloudtrail fileset #18644
Labels
Comments
leehinman
added
enhancement
Filebeat
Filebeat
needs_backport
PR is waiting to be backported to other branches.
Team:SIEM
labels
May 19, 2020
Pinging @elastic/siem (Team:SIEM) |
We could use this both in rules and ML jobs for CloudTrail events. Most CloudTrail events are just records of API method calls which are often not inherently suspicious. The ability to consider the attributes of the client or caller network will be important in addition to the user context or creds. |
4 tasks
leehinman
added a commit
to leehinman/beats
that referenced
this issue
Jun 3, 2020
- add geoip AS lookup on source.ip - improve mappings event.category - improve mappings for event.type Closes elastic#18644
leehinman
added a commit
that referenced
this issue
Jun 5, 2020
- add geoip AS lookup on source.ip - improve mappings event.category - improve mappings for event.type Closes #18644
leehinman
added a commit
to leehinman/beats
that referenced
this issue
Jun 5, 2020
- add geoip AS lookup on source.ip - improve mappings event.category - improve mappings for event.type Closes elastic#18644 (cherry picked from commit c01dfe6)
4 tasks
leehinman
added a commit
that referenced
this issue
Jun 8, 2020
melchiormoulin
pushed a commit
to melchiormoulin/beats
that referenced
this issue
Oct 14, 2020
- add geoip AS lookup on source.ip - improve mappings event.category - improve mappings for event.type Closes elastic#18644
andrewkroh
removed
the
needs_backport
PR is waiting to be backported to other branches.
label
Dec 15, 2020
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Describe the enhancement:
Add source.as.organization.name to cloudtrail fileset
Describe a specific use case for the enhancement or feature:
** Backport
7.6, 7.7, 7.8, 7.x
The text was updated successfully, but these errors were encountered: