elastic / ecs

Elastic Common Schema
https://www.elastic.co/what-is/ecs
Apache License 2.0
987 stars 410 forks source link

Addition of additional allowed values for event.type #2308

Open thompson-tomo opened 6 months ago

thompson-tomo commented 6 months ago

Summary For the event.type Field, i Would like the following to be added as allowed values: role, policy & permission.

Motivation: I am wanting to use ELK to store all my access control audit information. With the current gap being recording changes to roles, policies & permission as both user & groups are supported.