-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Filebeat] Upgrade cef module to ECS 1.4 #16157
Comments
Pinging @elastic/siem (Team:SIEM) |
evaluated and no changes were needed. |
On further consideration should populate all related.user, related.ip & related.hash fields |
@leehinman Nice - we often forget to populate those fields, which are valuable for pivoting in SIEM timeline. |
I'm not sure how close we are to using the default pipeline (#14001), but the |
- related.hash - related.ip - related.user - fix description Closes elastic#16157 Closes elastic#16289
- related.hash - related.ip - related.user - fix description Closes elastic#16157 Closes elastic#16289 (cherry picked from commit 3e6edf2)
Filesets
The text was updated successfully, but these errors were encountered: