Support new ECS 1.6 fields
add support for new ECS fields from elastic/ecs#930 1.6.0 Changelog
Describe the enhancement:
elastic/ecs#762 ECS added support for storing common core fields
of X509 certificates. The following data sources should be looked at
to see if they can take advantage of the new fields:
Describe the enhancement:
elastic/ecs#763 added architecture & imphash for PE field set
Describe the enhancement:
elastic/ecs#816 Added more account and project cloud metadata.
Describe the enhancement:
elastic/ecs#907 Added event.reason for the reason why an event's
outcome or action was taken.
Describe the enhancement:
elastic/ecs#913 Added related.hosts to capture all hostnames and
host identifiers on an event.
Describe the enhancement:
elastic/ecs#917 Added user.roles to capture a list of role names
that apply to the user.
Support new ECS 1.6 fields
add support for new ECS fields from elastic/ecs#930 1.6.0 Changelog
Describe the enhancement:
elastic/ecs#762 ECS added support for storing common core fields
of X509 certificates. The following data sources should be looked at
to see if they can take advantage of the new fields:
Describe the enhancement:
elastic/ecs#763 added architecture & imphash for PE field set
Describe the enhancement:
elastic/ecs#816 Added more account and project cloud metadata.
Describe the enhancement:
elastic/ecs#907 Added
event.reasonfor the reason why an event'soutcome or action was taken.
Describe the enhancement:
elastic/ecs#913 Added
related.hoststo capture all hostnames andhost identifiers on an event.
Describe the enhancement:
elastic/ecs#917 Added
user.rolesto capture a list of role namesthat apply to the user.