Skip to content

[meta] ECS 8.5 Updates (Security External Integrations) #4338

@efd6

Description

@efd6

This is a meta issue to track ECS 8.5 updates to Fleet integrations maintained by the elastic/security-external-integrations team.

ECS 8.5 Changes

This is a summary of the changes in ECS 8.5. You can view the official changelog here.

Added

No features added to ECS in 8.5 required changes in SEI packages.

  • Adding risk.* fields as experimental.
  • Adding process.io.* as beta fields.
  • Adding process.tty.rows and process.tty.columns as beta fields.
  • Changed process.env_vars field type to be an array of keywords.
  • process.attested_user and process.attested_groups as beta fields.
  • Added risk.* fieldset to beta.

SEI owned Integrations

All SEI integrations are updated in #4285 (currently updating to v8.5.0-rc1).

Prior to this PR a number of preparatory PRs were required to bring packages up to date:

Integrations SEI contributes to

I reviewed these to see if they were affected any changes to ECS; as above no changes in the ECS have any impact in these packages and they will not be touched.

  • aws.cloudtrail
  • aws.vpcflow
  • system.application
  • system.auth
  • system.security
  • system.system
  • windows.forwarded
  • windows.powershell
  • windows.powershell_operational
  • windows.sysmon_operational

Metadata

Metadata

Assignees

Labels

8.5 candidateenhancementNew feature or requestintegrationLabel used for meta issues tracking each integration

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions