Skip to content

[Filebeat][Fortinet] Fortinet ingest pipeline should set event.kind: alert #22136

@ijokarumawak

Description

@ijokarumawak

Describe the enhancement:
Fortinet ingest pipeline should set event.kind: alert if fortinet.firewall.attack field is set.

Describe a specific use case for the enhancement or feature:
Filebeat Paloalt module has its ingest pipeline to set event.kind: alert if ctx?.panw?.panos?.type == "THREAT". So analysts can see such events at SIEM Overview 'External alert trend' graph. But Fortinet module doesn't have such logic and its kind is always event.kind: event. Fortinet module should implement the similar logic.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions