Skip to content

[Winlogbeat] Sysmon module - populate pe.original_file_name #17335

@andrewkroh

Description

@andrewkroh

Sysmon v10.0 added OriginalFileName to process create and load image events. And ECS 1.5 added pe.original_file_name. Winlogbeat's Sysmon module should be updated to populate this field.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions