Skip to content

Improve documentation to ensure source/destination are populated as a priority #948

@webmat

Description

@webmat

The definition of the Client & Server field sets are pretty extensive, whereas Source & Destination's definitions are pretty bare.

We've been encouraging people to populate source & destination as a baseline, and client & server only when relevant or helpful. Elastic Security mostly considers source & destination.

However the ECS documentation doesn't make that obvious. There's only a vague mention about prioritizing source/destination in the client/server definitions. No mention of this in source/destination.

  • Expand definitions of source and destination field sets #967 We should expand the definitions of the source & destination field sets to clearly state that they are the baseline, compared to client & server.
  • Add mapping network event guidance doc #969 We could also consider having a standalone documentation page that talks about capturing network related events holistically. It could cover:
    • the src/dst baseline, and showcase when cli/srv are useful (e.g. DNS)
    • it could discuss populating the network.* fields
    • it could discuss how event.category:network + event.type:protocol should always come with network.protocol:[appropriate protocol name]. Most category/type pairs are complete on their own. But not the pair network/protocol; it should come with network.protocol.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions