Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat] Improve ECS field mappings in aws module #16307

Merged
merged 3 commits into from
Feb 21, 2020

Commits on Feb 13, 2020

  1. Improve ECS field mappings in aws module

    - elb fileset
      + cloud.provider
      + event.category
      + event.kind
      + event.outcome
      + http.response.status_code, convert to long
      + http.request.method, lowercase
      + tracing.trace.id
    
    - s3access fileset
      + client.address
      + client.ip
      + geo
      + client.user.id
      + cloud.provider
      + event.action
      + event.code
      + event.duration
      + event.id
      + event.kind
      + event.outcome
      + http.request.referrer
      + http.response.status_code
      + related.user
      + user_agent
    
    - vpcflow fileset
      + cloud.provider
      + cloud.account.id
      + cloud.instance.id
      + event.kind
    
    Closes elastic#16154
    leehinman committed Feb 13, 2020
    Configuration menu
    Copy the full SHA
    0539c3e View commit details
    Browse the repository at this point in the history

Commits on Feb 19, 2020

  1. implement feedback

    - improve grok pattern to make status code a long
    - make status code check more readable
    - add remote_ip to related.ip
    leehinman committed Feb 19, 2020
    Configuration menu
    Copy the full SHA
    98ce21c View commit details
    Browse the repository at this point in the history

Commits on Feb 20, 2020

  1. Configuration menu
    Copy the full SHA
    6d805c3 View commit details
    Browse the repository at this point in the history