Skip to content

Crowdstrike FDR Mapping Enhancement #4040

@jamiehynds

Description

@jamiehynds

related.ip
Our FDR pipeline currently adds observer.ip, source.ip and destination.ip to related.hosts but customer feedback suggests, it should be added be added to related.ip field instead of related.hosts.
https://github.com/elastic/integrations/blob/main/packages/crowdstrike/data_stream/fdr/elasticsearch/ingest_pipeline/default.yml#L1342
https://github.com/elastic/integrations/blob/main/packages/crowdstrike/data_stream/fdr/elasticsearch/ingest_pipeline/default.yml#L1834
https://github.com/elastic/integrations/blob/main/packages/crowdstrike/data_stream/fdr/elasticsearch/ingest_pipeline/default.yml#L1839

crowdstrike.FirstSeen
Customer has suggested this field is mapped to @timestamp. What field do we currently rely on to generate the timestamp? We do have a threat.indicator.first_seen but not a good fit here, as it relates more to IOC's.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions