-
Notifications
You must be signed in to change notification settings - Fork 562
Invalid ECS field usages at root-level #7808
Copy link
Copy link
Closed
Labels
Integration:1password1Password (Partner supported)1Password (Partner supported)Integration:azure_frontdoorAzure Frontdoor (Community supported)Azure Frontdoor (Community supported)Integration:carbonblack_edrVMware Carbon Black EDRVMware Carbon Black EDRIntegration:cisco_aironetCisco Aironet (Community supported)Cisco Aironet (Community supported)Integration:cisco_merakiCisco MerakiCisco MerakiIntegration:cloudflare_logpushCloudflare LogpushCloudflare LogpushIntegration:crowdstrikeCrowdStrikeCrowdStrikeIntegration:fireeyeFireEye Network Security (Community supported)FireEye Network Security (Community supported)Integration:infoblox_niosInfoblox NIOSInfoblox NIOSIntegration:juniper_srxJuniper SRXJuniper SRXIntegration:netflowNetFlow RecordsNetFlow RecordsIntegration:panwPalo Alto Next-Gen FirewallPalo Alto Next-Gen FirewallIntegration:sentinel_oneSentinelOneSentinelOneIntegration:trend_micro_vision_oneTrendAI Vision OneTrendAI Vision OnebugSomething isn't working, use only for issuesSomething isn't working, use only for issues
Metadata
Metadata
Assignees
Labels
Integration:1password1Password (Partner supported)1Password (Partner supported)Integration:azure_frontdoorAzure Frontdoor (Community supported)Azure Frontdoor (Community supported)Integration:carbonblack_edrVMware Carbon Black EDRVMware Carbon Black EDRIntegration:cisco_aironetCisco Aironet (Community supported)Cisco Aironet (Community supported)Integration:cisco_merakiCisco MerakiCisco MerakiIntegration:cloudflare_logpushCloudflare LogpushCloudflare LogpushIntegration:crowdstrikeCrowdStrikeCrowdStrikeIntegration:fireeyeFireEye Network Security (Community supported)FireEye Network Security (Community supported)Integration:infoblox_niosInfoblox NIOSInfoblox NIOSIntegration:juniper_srxJuniper SRXJuniper SRXIntegration:netflowNetFlow RecordsNetFlow RecordsIntegration:panwPalo Alto Next-Gen FirewallPalo Alto Next-Gen FirewallIntegration:sentinel_oneSentinelOneSentinelOneIntegration:trend_micro_vision_oneTrendAI Vision OneTrendAI Vision OnebugSomething isn't working, use only for issuesSomething isn't working, use only for issues
Type
Fields
Give feedbackNo fields configured for issues without a type.
Across packages owned by elastic/security-external-integrations the following fields are being used at the document root, but according to ECS they are only allowed be nested under other ECS namespaces like
hostorsource. These usages need to be changed to align with ECS. And fixing these issues will be required to move to package-spec 3.0.0.This was detected by looking at fields.yml mappings only. It's possible that the fields are not actually used in some cases. If I accidentally included a deprecated or rsa2elk package then please ignore that field.
Source Locations
(List generated with an agg on top of query
@attributes.deprecated:false and @attributes.rsa2elk:false and @owner:elastic/security-external-integrations and @type:field and name:(vlan.id or geo.continent_name or os.type or interface.id or os.name or interface.name or as.number or os.name or os.name or as.number or os.family or os.type or interface.name or x509.issuer.common_name or geo.city_name)to https://github.com/andrewkroh/go-examples/tree/main/fleetpkg-indexer)