-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Auditbeat populating unexpected value of ECS event.kind field #26790
Comments
botelastic
bot
added
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Jul 8, 2021
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
botelastic
bot
removed
the
needs_team
Indicates that the issue/PR needs a Team:* label
label
Jul 8, 2021
IIRC at the time we concluded it was a breaking change so we did not backport it. It is something we can discuss still @MikePaquette |
I think we can change it without affecting much. I opened #27721. |
Backported this fix for 7.16. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Version: 7.14.0 BC1
Operating System: macOS
Discuss Forum URL: None
Steps to Reproduce: install auditbeat on macOS system. Force quit a process. Look for error events from auditbeat.
Detected by: custom security solution detection rule "ECS Check: event.kind contains disallowed value"
Expected behavior:
event.kind
should be one of {alert, event, metric, state, pipeline_error, signal} per docs.Observed behavior:
event.kind: error
Screenshot:
Actual event output below:
The text was updated successfully, but these errors were encountered: