Skip to content

Permit event.type: access for event.category: file events#2174

Merged
ebeahan merged 2 commits intoelastic:mainfrom
ebeahan:add-access-to-file-category
Feb 23, 2023
Merged

Permit event.type: access for event.category: file events#2174
ebeahan merged 2 commits intoelastic:mainfrom
ebeahan:add-access-to-file-category

Conversation

@ebeahan
Copy link
Copy Markdown
Member

@ebeahan ebeahan commented Feb 23, 2023

Currently, events categorized as event.category: file do not list access as an expected event type.

I believe this is likely an oversight when the ECS categorization fields were originally defined. This PR proposes adding access as one of the allowed types for file.

@ebeahan ebeahan requested a review from a team as a code owner February 23, 2023 14:27
@ebeahan ebeahan self-assigned this Feb 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants