Skip to content

Commit

Permalink
[Filebeat] Improve ECS field mappings in suricata module (elastic#16843)
Browse files Browse the repository at this point in the history
* Improve ECS field mappings in suricata module

- destination.domain
- dns.question.top_level_domain
- event.category
- event.kind
- event.outcome
- event.type
- related.hash
- related.ip
- rule.category
- rule.id
- rule.name
- tls.client.server_name
- tls.resumed
- tls.server.certificate
- tls.server.certificate_chain
- tls.server.hash.sha1
- tls.server.issuer
- tls.server.ja3s
- tls.server.not_after
- tls.server.not_before
- tls.server.subject
- tls.version
- tls.version_protocol

Closes elastic#16181
  • Loading branch information
leehinman authored Mar 12, 2020
1 parent 3e6edf2 commit 7eb2fba
Show file tree
Hide file tree
Showing 6 changed files with 1,015 additions and 207 deletions.
1 change: 1 addition & 0 deletions CHANGELOG.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -179,6 +179,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Improve ECS categorization field mappings in ibmmq module. {issue}16163[16163] {pull}16532[16532]
- Improve ECS categorization, host field mappings in elasticsearch module. {issue}16160[16160] {pull}16469[16469]
- Add ECS related fields to CEF module {issue}16157[16157] {pull}16338[16338]
- Improve ECS categorization field mappings in suricata module. {issue}16181[16181] {pull}16843[16843]

*Heartbeat*

Expand Down
Loading

0 comments on commit 7eb2fba

Please sign in to comment.