Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Winlogbeat] Improve ECS field mappings in Sysmon module. #18381

Merged
merged 1 commit into from
May 14, 2020

Commits on May 14, 2020

  1. Improve ECS field mappings in Sysmon module.

    - related.hash, related.ip, and related.user are now populated.
    - hashes are now also populated to the corresponding process.hash, process.pe.imphash, file.hash or file.pe.imphash
    - file.name, file.directory, and file.extension are now populated.
    - rule.name is populated for all events when present.
    
    Closes elastic#18364
    marc-gr committed May 14, 2020
    Configuration menu
    Copy the full SHA
    eef083f View commit details
    Browse the repository at this point in the history