For the trendmicro integration, the default pipeline sets event.category: network and event.type: [connection,access,allowed,denied,info]. Having these categorization fields mass applied to all events makes it more difficult for users to gain insight into the events.
For the
trendmicro
integration, the default pipeline setsevent.category: network
andevent.type: [connection,access,allowed,denied,info]
. Having these categorization fields mass applied to all events makes it more difficult for users to gain insight into the events.ECS
event.category
allowed values: https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-category.html ECSevent.type
allowed values: https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-type.html