Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Filebeat cisco/asa and ftd sets event.outcome to a non-conforming value #20253

Closed
adriansr opened this issue Jul 27, 2020 · 3 comments
Closed
Labels
bug Filebeat Filebeat help wanted Indicates that a maintainer wants help on an issue or pull request Stalled

Comments

@adriansr
Copy link
Contributor

The shared ingest pipeline sets event.outcome to allow or deny, instead of using one of the values allowed by ECS:

  • failure
  • success
  • unknown
@adriansr adriansr added bug Filebeat Filebeat help wanted Indicates that a maintainer wants help on an issue or pull request labels Jul 27, 2020
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Jul 27, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Jul 27, 2020
@BenB196
Copy link

BenB196 commented Jul 28, 2020

Just an fyi, this is a related issue: #19943

@adriansr adriansr changed the title Filebeat cisco/asa and ftd set event.outcome to a non-conforming value Filebeat cisco/asa and ftd sets event.outcome to a non-conforming value Jul 28, 2020
@botelastic
Copy link

botelastic bot commented Jun 28, 2021

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@botelastic botelastic bot added the Stalled label Jun 28, 2021
@botelastic botelastic bot closed this as completed Jul 28, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Filebeat Filebeat help wanted Indicates that a maintainer wants help on an issue or pull request Stalled
Projects
None yet
Development

No branches or pull requests

3 participants