Closed adriansr closed 5 years ago
Pinging @elastic/secops
ECS fields for Biflow support:
Non-Biflow flows:
event.kind: event
event.category: network_traffic
event.action: netflow_flow
Biflow flows:
event.kind: event
event.category: network_session
event.action: netflow_flow
Netflow options:
event.kind: event
event.category: network_traffic
event.action: netflow_options
https://tools.ietf.org/html/rfc5103#section-6.3 shows how we would map source.*
and destination.*
to client.*
and server.*
Information Element Field = 0x00, 0x01, 0x03
source.*
-> copy_to -> client.*
destination.*
-> copy_to -> server.*
Information Element Field = 0x02
source.*
-> copy_to -> server.*
destination.*
-> copy_to -> client.*
( @MikePaquette suggestion )
6.6 Release checklist
flow
. ( See this comment)
*.locality
fields.flow.id
can be removed later while in beta, but it's kind of useful for visualizing to have a single field with the flow ID even if it's unique to an application (e.g. packetbeat flow IDs can't correlate with Suricata or Bro, but they all have their own ID concept).flow
is to be removed, it can be done in this PR. #9609Backports to 6.x / 6.6. Merge in given order
source
with ecs_source
// ---> #9646
Filebeat NetFlow input release checklist
This checklist is intended to track progress of NetFlow support in Filebeat (#8434).
For this input and associated modules to go GA, the following criterias should be met:
netflow
input. (#9365)netflow
input. (#9388)