Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat] Upgrade panw module to ECS 1.4 #16025

Closed
1 task
leehinman opened this issue Feb 3, 2020 · 1 comment · Fixed by #17910
Closed
1 task

[Filebeat] Upgrade panw module to ECS 1.4 #16025

leehinman opened this issue Feb 3, 2020 · 1 comment · Fixed by #17910
Assignees

Comments

@leehinman
Copy link
Contributor

leehinman commented Feb 3, 2020

Filesets

  • panos

look at threat & rule fields

@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@leehinman leehinman changed the title [Filebeat] Update panos fileset to support ECS 1.4 fields [Filebeat] Upgrade panw module to ECS 1.4 Feb 6, 2020
@leehinman leehinman added the ecs label Feb 6, 2020
@leehinman leehinman self-assigned this Apr 21, 2020
leehinman added a commit to leehinman/beats that referenced this issue Apr 22, 2020
- panw.panos.action
- event.outcome, limit to succes/failure
- event.kind
- event.category, make array
- event.type, make array
- rule.name
- related.user

Closes elastic#16025
leehinman added a commit that referenced this issue Apr 23, 2020
- panw.panos.action
- event.outcome, limit to succes/failure
- event.kind
- event.category, make array
- event.type, make array
- rule.name
- related.user

Closes #16025
leehinman added a commit to leehinman/beats that referenced this issue Apr 23, 2020
- panw.panos.action
- event.outcome, limit to succes/failure
- event.kind
- event.category, make array
- event.type, make array
- rule.name
- related.user

Closes elastic#16025

(cherry picked from commit e174441)
leehinman added a commit that referenced this issue Apr 29, 2020
…anw module (#17943)

* Improve ECS field mappings in panw module (#17910)

- panw.panos.action
- event.outcome, limit to succes/failure
- event.kind
- event.category, make array
- event.type, make array
- rule.name
- related.user
- mage fmt update

Closes #16025

(cherry picked from commit e174441)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants