Description of the issue:
The ECS docs say
When only a single certificate is logged in an event, it should be nested under file.
This could be interpreted to apply when dealing with a TLS connection where only the server presents a certificate. The text here could be reworked to clarify when to use file vs tls.server/client.
Description of the issue:
The ECS docs say
This could be interpreted to apply when dealing with a TLS connection where only the server presents a certificate. The text here could be reworked to clarify when to use
filevstls.server/client.