Closed brett-fitz closed 3 months ago
@ebeahan This should be good to go and ready for discussion. Let me know if there are any issues with the PR! 😄
This PR is stale because it has been open for 60 days with no activity.
Looks ok to me but I would like to have another approval from ecs maintainers / security folks
@mjwolf could you check it as well?
@trisch-me @mjwolf My organization has dissolved and formed into a new entity. I'm going to resubmit this PR under a branch off my personal fork with the requested changes from above.
Closing this PR. Now please refer to the new one: https://github.com/elastic/ecs/pull/2324
Added
threat.indicator.id
field. Resolves #2252.The new field
threat.indicator.id
will allow for security systems to append a threat.indicator.id. This field can have multiple values to allow for the identification of the same indicator across systems that use different ID formats.Common serialization format you may expect to see here is a STIX 2.x indicator id. Here is an example of one being produced.