Closed cwurm closed 5 years ago
New fields used in the Auditbeat system module that need to be added to fields.ecs.yml:
fields.ecs.yml
network.type
process.start
process.working_directory
event.kind
Pinging @elastic/secops
All of these have been added in https://github.com/elastic/beats/pull/9121.
New fields used in the Auditbeat system module that need to be added to
fields.ecs.yml
:network.type
(used in the socket metricset)process.start
andprocess.working_directory
(used in the process metricset)event.kind
(everywhere)