Skip to content

[auditd] Missing event.original mapping #4005

@andrewkroh

Description

@andrewkroh

The auditd integration is missing a mapping for event.original. The cause can be attributed to missing validation related to elastic/elastic-package#147.

% go run github.com/andrewkroh/go-examples/fields-yml@main packages/auditd/data_stream/log/fields/*.yml \
  | grep event.original
% echo $?
1

Metadata

Metadata

Assignees

Labels

Integration:auditdAuditd LogsbugSomething isn't working, use only for issues

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions