Skip to content

Commit

Permalink
[Winlogbeat] Use ingress/egress instead of inbound/outbound (#22997)
Browse files Browse the repository at this point in the history
* [Winlogbeat] Use ingress/egress instead of inbound/outbound

* Add changelog entry
  • Loading branch information
Andrew Stucki authored Dec 9, 2020
1 parent 713190f commit 12af688
Show file tree
Hide file tree
Showing 3 changed files with 20 additions and 19 deletions.
1 change: 1 addition & 0 deletions CHANGELOG.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Fix Powershell processing of downgraded engine events. {pull}18966[18966]
- Fix unprefixed fields in `fields.yml` for Powershell module {issue}18984[18984]
- Remove top level `hash` property from sysmon events {pull}20653[20653]
- Use ECS 1.7 ingress/egress instead of inbound/outbound network.direction in sysmon. {pull}22997[22997]

*Functionbeat*

Expand Down
4 changes: 2 additions & 2 deletions x-pack/winlogbeat/module/sysmon/config/winlogbeat-sysmon.js
Original file line number Diff line number Diff line change
Expand Up @@ -357,10 +357,10 @@ var sysmon = (function () {
var addNetworkDirection = function (evt) {
switch (evt.Get("winlog.event_data.Initiated")) {
case "true":
evt.Put("network.direction", "outbound");
evt.Put("network.direction", "egress");
break;
case "false":
evt.Put("network.direction", "inbound");
evt.Put("network.direction", "ingress");
break;
}
evt.Delete("winlog.event_data.Initiated");
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -476,7 +476,7 @@
},
"network": {
"community_id": "1:EQDBfI6vAylArTBQHY8kNmaweOA=",
"direction": "outbound",
"direction": "egress",
"protocol": "domain",
"transport": "udp",
"type": "ipv6"
Expand Down Expand Up @@ -550,7 +550,7 @@
},
"network": {
"community_id": "1:TXczQujzvcGYSvZ/CKEBu1p2riE=",
"direction": "inbound",
"direction": "ingress",
"protocol": "domain",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -625,7 +625,7 @@
},
"network": {
"community_id": "1:W2ZbP8nXMY+YAGYw2h/3Sa8Gu/w=",
"direction": "outbound",
"direction": "egress",
"protocol": "https",
"transport": "tcp",
"type": "ipv4"
Expand Down Expand Up @@ -700,7 +700,7 @@
},
"network": {
"community_id": "1:5MsyqYltV9KkhIFGPWiByzQqHDo=",
"direction": "outbound",
"direction": "egress",
"protocol": "https",
"transport": "tcp",
"type": "ipv4"
Expand Down Expand Up @@ -775,7 +775,7 @@
},
"network": {
"community_id": "1:0p51df9oGzNph3fcneX2H8jXsag=",
"direction": "outbound",
"direction": "egress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -854,7 +854,7 @@
},
"network": {
"community_id": "1:0p51df9oGzNph3fcneX2H8jXsag=",
"direction": "inbound",
"direction": "ingress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -931,7 +931,7 @@
},
"network": {
"community_id": "1:4DSgubObvMEI9IKNWPDqltrux+k=",
"direction": "outbound",
"direction": "egress",
"protocol": "llmnr",
"transport": "udp",
"type": "ipv6"
Expand Down Expand Up @@ -1006,7 +1006,7 @@
},
"network": {
"community_id": "1:sejGGvgk92xTvKdzlFitndKqdWw=",
"direction": "outbound",
"direction": "egress",
"protocol": "llmnr",
"transport": "udp",
"type": "ipv6"
Expand Down Expand Up @@ -1080,7 +1080,7 @@
},
"network": {
"community_id": "1:yP71IXofOTWmF1LG760//yXa4Rk=",
"direction": "outbound",
"direction": "egress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -1157,7 +1157,7 @@
},
"network": {
"community_id": "1:yP71IXofOTWmF1LG760//yXa4Rk=",
"direction": "inbound",
"direction": "ingress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -1234,7 +1234,7 @@
},
"network": {
"community_id": "1:Zt/ImHlMNf4MciHXlRDkivgw2jY=",
"direction": "outbound",
"direction": "egress",
"protocol": "llmnr",
"transport": "udp",
"type": "ipv6"
Expand Down Expand Up @@ -1308,7 +1308,7 @@
},
"network": {
"community_id": "1:SHkoHfPFDYWai8qQBwIiRxvCPZw=",
"direction": "outbound",
"direction": "egress",
"protocol": "llmnr",
"transport": "udp",
"type": "ipv6"
Expand Down Expand Up @@ -1382,7 +1382,7 @@
},
"network": {
"community_id": "1:DI+g4BImhWaUwPmLEjdMMQVYPLs=",
"direction": "outbound",
"direction": "egress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -1460,7 +1460,7 @@
},
"network": {
"community_id": "1:okFVyky/zOY2Q0BATy37YsbiveA=",
"direction": "outbound",
"direction": "egress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -1538,7 +1538,7 @@
},
"network": {
"community_id": "1:ZHyFuF2PjubLSbAh4zRQIZHOZK8=",
"direction": "outbound",
"direction": "egress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -1616,7 +1616,7 @@
},
"network": {
"community_id": "1:r3C/WjbATNIislTQ0M+ySzwnuiw=",
"direction": "outbound",
"direction": "egress",
"protocol": "netbios-ns",
"transport": "udp",
"type": "ipv4"
Expand Down Expand Up @@ -2143,4 +2143,4 @@
"version": 4
}
}
]
]

0 comments on commit 12af688

Please sign in to comment.