You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Use of basic types with wildcard elastic/dev#1508 elastic/ecs#970:
(important note: Going with option 2 will require each Beat to implement this fallback mechanism to replace wildcard to keyword, when posting an index template to Elasticsearch.)
Required changes to upgrade beats modules to 1.7:
Using https://github.com/elastic/ecs-dev/issues/199 as reference:
Experimental
Use of basic types with wildcard elastic/dev#1508 elastic/ecs#970:
(important note: Going with option 2 will require each Beat to implement this fallback mechanism to replace wildcard to keyword, when posting an index template to Elasticsearch.)
Multiple users in an event elastic/ecs#914
Additions in 1.7:
New
ingressandegressallowed values fornetwork.directionelastic/ecs#945:Filebeat cisco umbrella(waiting on CIDR matching processors/painless support in elasticsearch Painless convenience function for matching IP addresses elasticsearch#60668)Filebeat rsa2elk modules(@adriansr) (need to add individual module configuration support, see Add network.direction classification to rsa2elk modules #23114)HTTP request/response mime type elastic/ecs#944:
(important note: needs to analyze body)
Filebeat o365(doesn't capture request/response body)Filebeat gsuite(doesn't capture request/response body)Filebeat suricata eve(doesn't capture request/response body)Filebeat rsa2elk modules(doesn't capture request/response body)Filebeat checkpoint firewall(doesn't capture request/response body)Filebeat cef(doesn't capture request/response body)Filebeat cisco ftd(doesn't capture request/response body)Filebeat cisco umbrella(doesn't capture request/response body)Filebeat fortinet clientendpoint(doesn't capture request/response body)Filebeat fortinet firewall(doesn't capture request/response body)Filebeat fortinet fortimail(doesn't capture request/response body)Filebeat fortinet fortimanager(doesn't capture request/response body)Filebeat panw panos(doesn't capture request/response body)Filebeat sophos xg(doesn't capture request/response body)Filebeat zeek http(doesn't capture request/response body)New allowed value
configurationforevent.categoryelastic/ecs#963:Auditbeat system(no configuration events to be classified)Filebeat Okta(no configuration events to be classified)Filebeat microsoft(check if rsa2elk microsoft modules need updating)Filebeat rsa2elk modules(currently we don't do any event categorization)Add
subdomaindomain breakdown across all domain breakdowns (currently only indns) elastic/ecs#981:Packetbeat(seems done fordns)