Skip to content

fireeye using invalid field values according to ECS #3053

@jsoriano

Description

@jsoriano
[0] parsing field value failed: field "event.type"'s value "dns" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)
[1] parsing field value failed: field "event.type"'s value "fileinfo" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)
[2] parsing field value failed: field "event.type"'s value "flow" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)
[3] parsing field value failed: field "event.type"'s value "tls" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)

Part of #3016

Metadata

Metadata

Assignees

Labels

Integration:fireeyeFireEye Network Security (Community supported)

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions