ECS 1.9 user.changes.*, user.effective.*, user.target.*#25754
ECS 1.9 user.changes.*, user.effective.*, user.target.*#25754janniten wants to merge 3 commits intoelastic:masterfrom janniten:ecs_1.9
Conversation
|
This pull request is now in conflicts. Could you fix it? 🙏 |
|
Hi! We're labeling this issue as |
|
ECS 1.9 new fields in order to capture n-ary user relationships |
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
|
@janniten thanks for this PR! there are some merge conflicts, could you please take a look? cc @elastic/security-external-integrations |
What does this PR do?
In ECS 1.9 user.changes.*, user.effective.*, and user.target.* were introduced in order to capture better those events in where many users are involved. This fields allows us to model complex user's relationships.
See improvements sections in https://github.com/elastic/ecs/releases
Why is it important?
According to the usage described in https://www.elastic.co/guide/en/ecs/current/ecs-user-usage.html modifications to the winlogbeat security module are introduced in this PR in order to model user's relationship in an event.
Checklist
CHANGELOG.next.asciidocorCHANGELOG-developer.next.asciidoc.Author's Checklist
Use cases
The events affected are