Open leweafan opened 1 year ago
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
Seems that related.ip not added by ingest pipeline but by filebeat here and fields names:
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)
Describe the enhancement:
Add ip fields below to related.ip for netflow module:
According to ECS field description:
Describe a specific use case for the enhancement or feature:
Missing ip in related.ip affects security issues discovery cause you can't be sure that all event' ip indeed present in related.ip.