Closed crisdarocha closed 9 months ago
Pinging @elastic/siem (Team:SIEM)
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
Hi! We just realized that we haven't looked into this issue in a while. We're sorry!
We're labeling this issue as Stale
to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1
.
Thank you for your contribution!
It‘s still relevant for us.
Hi! We just realized that we haven't looked into this issue in a while. We're sorry!
We're labeling this issue as Stale
to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1
.
Thank you for your contribution!
👍🏻
Describe the enhancement: In the Filebeat NetFlow module,
FW_EVENT
are numeric codes that are mapped tonetflow.firewall_event
.From the Cisco documentation, we have the meaning of the codes:
It would be great to have a new field, ECS compliant, that stores the "translated" human readable value for the
FW_EVENT
.Describe a specific use case for the enhancement or feature: Numeric codes are great for programatic analysis, but don't say much when humans try to understand the event lines. Enriching the data at pipeline level would add value to the analysis.