elastic / beats

:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
https://www.elastic.co/products/beats
Other
12.06k stars 4.89k forks source link

[Filebeat] Add human readable field with translation for FW_EVENT to NetFlow module #16296

Closed crisdarocha closed 9 months ago

crisdarocha commented 4 years ago

Describe the enhancement: In the Filebeat NetFlow module, FW_EVENT are numeric codes that are mapped to netflow.firewall_event.

From the Cisco documentation, we have the meaning of the codes:

Indicates a firewall event. The allowed values are:
0 - Ignore (invalid)
1 - Flow Created
2 - Flow Deleted
3 - Flow Denied
4 - Flow Alert
5 - Flow Update 

It would be great to have a new field, ECS compliant, that stores the "translated" human readable value for the FW_EVENT.

Describe a specific use case for the enhancement or feature: Numeric codes are great for programatic analysis, but don't say much when humans try to understand the event lines. Enriching the data at pipeline level would add value to the analysis.

elasticmachine commented 4 years ago

Pinging @elastic/siem (Team:SIEM)

botelastic[bot] commented 3 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

elasticmachine commented 3 years ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

botelastic[bot] commented 2 years ago

Hi! We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

abraxxa commented 2 years ago

It‘s still relevant for us.

botelastic[bot] commented 1 year ago

Hi! We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

abraxxa commented 9 months ago

👍🏻