ECS audit events for alerts plugin #80288
Labels
Feature:Security/Audit
Platform Security - Audit Logging feature
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
Team:Security
Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more!
In order to support better auditing capabilities across the stack we would like to add ECS audit events to alerts plugin:
Remove legacy audit events in alerts plugin:
alerts_authorization_failure
alerts_authorization_success
actions_authorization_failure
actions_authorization_success
Following auditing guidelines, create ECS audit events using the new audit service API:
Event types: https://docs.google.com/document/d/1J4iv3WhkfJqH241KmBPW6eOZGe4MbBz6XE_KlBL2-_s/edit#
The text was updated successfully, but these errors were encountered: