-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
filebeat azure module not mapping event.category for activitylogs #21190
Comments
Pinging @elastic/integrations-platforms (Team:Platforms) |
We'll be updating all the detection rules to remove These rules are targeted for the 7.10 release. |
@pwen090 do you have a list of expected values for azure.activitylogs.properties.eventCategory that we could use for a mapping to event.category ? |
Hi! We're labeling this issue as |
Filebeat Azure module does not seem to be mapping Azure activitylogs event.category field. This causes most Azure detections to fail. For example rules like "Azure Diagnostic Settings Deletion" will not match because event.category is missing. The event is shown in Elastic with category set within azure.activitylogs.properties.eventCategory but this does not seem to be mapped to event.category which the detection rules are looking for. Might be related to other mapping issues noted here: #20990
The text was updated successfully, but these errors were encountered: