Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Auditbeat system module fields to fields.ecs.yml #9318

Closed
cwurm opened this issue Nov 30, 2018 · 2 comments
Closed

Add Auditbeat system module fields to fields.ecs.yml #9318

cwurm opened this issue Nov 30, 2018 · 2 comments

Comments

@cwurm
Copy link
Contributor

cwurm commented Nov 30, 2018

New fields used in the Auditbeat system module that need to be added to fields.ecs.yml:

  1. network.type (used in the socket metricset)
  2. process.start and process.working_directory (used in the process metricset)
  3. event.kind (everywhere)
@elasticmachine
Copy link
Collaborator

Pinging @elastic/secops

@cwurm cwurm changed the title Add network.type to fields.ecs.yml Add Auditbeat system module fields to fields.ecs.yml Dec 4, 2018
@cwurm
Copy link
Contributor Author

cwurm commented Dec 18, 2018

All of these have been added in #9121.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants