-
Notifications
You must be signed in to change notification settings - Fork 562
aws vpcflow integration should properly set event.type #5478
Copy link
Copy link
Closed
Labels
Integration:awsAWSAWSTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]mapping/pipeline issue
Metadata
Metadata
Assignees
Labels
Integration:awsAWSAWSTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]mapping/pipeline issue
Type
Fields
Give feedbackNo fields configured for issues without a type.
For aws vpcflow integration with aws.vpcflow.action:REJECT, I only see event.outcome:failure. It should set event.type based on aws.vpcflow.action.
aws.vpcflow.action can be ACCEPT or REJECT according to https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html
@jamiehynds