Skip to content

Add Auditbeat system module fields to fields.ecs.yml #9318

@cwurm

Description

@cwurm

New fields used in the Auditbeat system module that need to be added to fields.ecs.yml:

  1. network.type (used in the socket metricset)
  2. process.start and process.working_directory (used in the process metricset)
  3. event.kind (everywhere)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions