Looking into the ECS documentation there is file.name, however
I would like to discuss and propose adding or documenting an additional file schema for source and destination (and or client/server where applicable).
This is especially useful in endpoint data and network transfers / file shares.
Moving or Copying File
scenario:
Renaming "payroll.docx" to "nothing_to_see_here.txt"
I am running into the same issue for ECS field mapping. I have an endpoint security data set that include source and destination folders paths and file names.
Looking into the ECS documentation there is
file.name
, however I would like to discuss and propose adding or documenting an additional file schema forsource
anddestination
(and orclient
/server
where applicable).This is especially useful in endpoint data and network transfers / file shares.
Moving or Copying File
scenario:
Renaming "payroll.docx" to "nothing_to_see_here.txt"
example: