-
Notifications
You must be signed in to change notification settings - Fork 562
[azure,o365,m365_defender] ECS mapping improvements #13989
Copy link
Copy link
Labels
Integration:azureAzure LogsAzure LogsIntegration:m365_defenderMicrosoft Defender XDRMicrosoft Defender XDRIntegration:o365Microsoft Office 365Microsoft Office 365Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Metadata
Metadata
Assignees
Labels
Integration:azureAzure LogsAzure LogsIntegration:m365_defenderMicrosoft Defender XDRMicrosoft Defender XDRIntegration:o365Microsoft Office 365Microsoft Office 365Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Type
Fields
Give feedbackNo fields configured for Enhancement.
Description
Various suggested ECS field mapping updates to improve correlation of ingested events with other security telemetry, for the integrations azure, o365 and m365_defender.
Similar to the earlier work for symantec_endpoint_security in #13476.