-
Notifications
You must be signed in to change notification settings - Fork 418
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add ECS categorization examples #860
Comments
Thanks @leehinman! @webmat and I have discussed improvements to the overall "Getting Started" experience of ECS in the documentation, and I agree these type of examples in the docs would be helpful for ECS end-users, implementers, and contributors alike. |
Yes we should work this into the documentation soon. Any additional examples you encounter would be welcome here. Thanks for opening this, Lee :-) |
Very minor point on example 4: IPS != IDS |
more on example4: for IPS, following the description [1] it would be beneficial to have also the action added to the event field:
What confuses me is the outcome field; that is from the IPS perspective if the connection was blocked the outcome should be So my question, how this is intended to be solved? [1] https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-type.html#ecs-event-type-denied |
The functionality to add more detailed usage documentation, touched on previously #860 (comment), has been added. Details can be found here. The ECS team plans to add some initial usage docs soon, which can also serve as examples for other contributions, but I thought I'd go ahead and share that the functionality is available! |
Summary:
We have documentation for each of the four buckets in ECS categorization, but we don't have examples of how all four buckets would be used together in real world examples.
Motivation:
Examples would help those implementing ECS to use the categorization buckets in a consistent manor.
Detailed Design:
Where in the documentation should we add these examples? Some options are:
values_section_header
inscripts/generators/asciidoc_fields.py
Examples:
The text was updated successfully, but these errors were encountered: