I noticed that many of the dns.* fields declared within the suricata.eve data stream are not importing the ECS definition. To ensure consistency across packages the data stream should use external: ecs for each of the fields that are available in ECS.
I noticed that many of the
dns.*
fields declared within thesuricata.eve
data stream are not importing the ECS definition. To ensure consistency across packages the data stream should useexternal: ecs
for each of the fields that are available in ECS.