Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Log ID Correlation Field Name #401

Closed
neu5ron opened this issue Mar 24, 2019 · 1 comment
Closed

Log ID Correlation Field Name #401

neu5ron opened this issue Mar 24, 2019 · 1 comment
Labels

Comments

@neu5ron
Copy link

neu5ron commented Mar 24, 2019

Would like to reopen the discussion on adding a related.id field ( I am also OK with log.id.
This field could either be a single value or an array depending on the log source / scenario. but regardless still a keyword ES type.
These would be dissimilar to event.id, because this proposed field would be the log source's internal identifier for correlating across multiple log types that it is. Also, this is distinct from the unique number/id of the log itself that the log source uses to prevent collisions or what not in its own internal logging database/function/system.

Four log sources that could immediately benefit:

  • Windows Event Log (WEF) field ActivityID
    correlating multiple different EventIDs
  • Bro (Zeek) field uid
    correlating multiple different log types. ex: conn <> ssl <> file <> x509 <> intel
  • Suricata field flow_id
    correlating flow log <> application log <> alert log
  • PaloAlto field Session ID
    correlating traffic <> threat <>

** Side note, the above fields aren't exhaustive. example Bro has at least over 10+ other's and WEF has a whole lot of em **

Reference to #67
but I wanted to potentially add clarity by adding more use cases and splitting this related log id into its own discussion.

@neu5ron neu5ron changed the title Log ID Coorelation Filed Name Log ID Correlation Filed Name Mar 24, 2019
@ebeahan ebeahan changed the title Log ID Correlation Filed Name Log ID Correlation Field Name Sep 15, 2020
@ebeahan ebeahan added the discuss label Dec 1, 2020
@ebeahan
Copy link
Member

ebeahan commented Aug 2, 2021

We created meta-issue ##1547 to assess correlated event support in ECS. Closing in favor of the meta issue.

@ebeahan ebeahan closed this as completed Aug 5, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants