Skip to content

Missing Parsing for Event IDs 4797, 5379, 5380, 5381, and 5382 #34293

@MakoWish

Description

@MakoWish

Describe the enhancement: Event ID's 4797, 5379, 5381, and 5382 are not currently parsed in the Winlogbeat 8.x Ingest Pipelines.

Describe a specific use case for the enhancement or feature: These are common Event ID's in our environment, so ensuring proper parsing will help with identifying events based on the event.action field.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs_teamIndicates that the issue/PR needs a Team:* label

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions