You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our team is currently working on Azure rules and it appears that event.category in the Azure module has incorrect field mappings. We are seeing event.category:Administrative for Activity logs and event.category:AuditLogs for Audit logs. According to the documentation, neither appear to be valid values. Example issue with screenshot - elastic/detection-rules#197.
For confirmed bugs, please report:
Version: 7.8.1
Operating System: all
Discuss Forum URL: n/a
Steps to Reproduce: Configure the Azure Filebeat module to send data to ES. Obsever the event.category field.
Screenshots
The text was updated successfully, but these errors were encountered:
spoke to @leehinman. looks like this is a non issue in version 7.9. I have not confirmed, but will close based on his feedback pointing to this PR - #19376
Description
Our team is currently working on Azure rules and it appears that
event.category
in the Azure module has incorrect field mappings. We are seeingevent.category:Administrative
for Activity logs andevent.category:AuditLogs
for Audit logs. According to the documentation, neither appear to be valid values. Example issue with screenshot - elastic/detection-rules#197.For confirmed bugs, please report:
event.category
field.Screenshots
The text was updated successfully, but these errors were encountered: