Skip to content

o365 using invalid field values according to ECS #3048

@jsoriano

Description

@jsoriano

[0] parsing field value failed: field "event.type"'s value "authentication_failure" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)
"authentication_failure" => "access", and use "event.outcome" to indicate the failure.

Part of #3016

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions