-
Notifications
You must be signed in to change notification settings - Fork 444
New field event.provider #321
Copy link
Copy link
Closed
Description
I have multiple log types with field named like "source" which is some component/provider of the log. If possible I use non-ECS event.logger field but in fact it is not usable here (logger can be some part of application like class/module itself). I noticed in https://github.com/elastic/beats/pull/10333/files it is named winlog.provider_name but it should be more general and part of ECS because Windows Event log is not the only log type which uses it. So I propose to add "event.provider" field.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Fields
Give feedbackNo fields configured for issues without a type.