[system] Add support for more event-ids in the security data stream#13828
[system] Add support for more event-ids in the security data stream#13828marc-gr merged 14 commits intoelastic:mainfrom
Conversation
|
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
|
Hi @jamiehynds ,@kcreddy , @efd6, |
|
LGMT in general, just a couple of things:
|
|
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
|
@marc-gr - If you are done with review, can you help me with your approval please? |
marc-gr
left a comment
There was a problem hiding this comment.
LGTM just needs to fix the changelog/manifest
nfritts
left a comment
There was a problem hiding this comment.
Approving for the linux team... I'm not sure they really have anything to contribute to this PR even though they own a couple of the files.
@marc-gr I have fixed the changelog and manifest. |
|
@marc-gr @janvi-elastic is this PR ready for merge yet or still waiting on CI to pass? |
@jamiehynds – Everything is done from our side, except for the CI issue, which we aren’t able to fix from our end. @marc-gr Let me know if there’s anything else you’re expecting from us. |
@piyush-elastic, as per the CI error: You could ignore numeric fields using |
🚀 Benchmarks reportTo see the full report comment with |
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
💚 Build Succeeded
History
|
|
|
@kcreddy - We have followed your comment and could see CI ran successfully. Kindly have a look and help with your approval please. |
|
Package system - 2.5.0 containing this change is available at https://epr.elastic.co/package/system/2.5.0/ |
|
Hi @janvi-elastic Could it be related to this PR ? Looking at one of the Agent configurations updated here, probably there is an extra cc @marc-gr |
|
We are reverting the |




Proposed commit message
This PR adds support for more event-ids of
Security Eventstosystem.security. These events have an event.code as below:System fields are mapped to their corresponding ECS fields where possible. And also added associated dashboards and visualizations.
Test samples were derived from live logs and documentation and subsequently sanitized.
Checklist
How to test this PR locally
Related issues
Screenshot