Skip to content

[Windows] Add support for event IDs 5137 and 5141 in forwarded data streams#17079

Merged
moxarth-rathod merged 3 commits intoelastic:mainfrom
moxarth-rathod:fix-ecs-field-25903
Feb 19, 2026
Merged

[Windows] Add support for event IDs 5137 and 5141 in forwarded data streams#17079
moxarth-rathod merged 3 commits intoelastic:mainfrom
moxarth-rathod:fix-ecs-field-25903

Conversation

@moxarth-rathod
Copy link
Copy Markdown
Contributor

Proposed commit message

windows: add support for event IDs 5137 and 5141 in forwarded data streams

Added ECS categorization for directory service object creation (5137) and deletion (5141) events. 
Includes new field mappings for AppCorrelationID, DSName, DSType, ObjectClass, ObjectDN, ObjectGUID, 
OpCorrelationID, and TreeDelete.

Test logs were generated from documentation.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/windows directory.
  • Run the following command to run tests.

elastic-package test

@moxarth-rathod moxarth-rathod self-assigned this Jan 28, 2026
@moxarth-rathod moxarth-rathod requested review from a team as code owners January 28, 2026 05:50
@moxarth-rathod moxarth-rathod added enhancement New feature or request Integration:windows Windows Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Jan 28, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

elastic-vault-github-plugin-prod bot commented Jan 28, 2026

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@pierrehilbert pierrehilbert added the Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] label Jan 28, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

@andrewkroh andrewkroh added the Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] label Jan 28, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

Co-authored-by: Tiago Queiroz <github@queiroz.life>
@narph
Copy link
Copy Markdown
Contributor

narph commented Feb 18, 2026

cc @marc-gr , can you have a quick look?

@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

History

cc @moxarth-rathod

@moxarth-rathod moxarth-rathod merged commit b4a0d8a into elastic:main Feb 19, 2026
9 checks passed
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

Package windows - 3.5.0 containing this change is available at https://epr.elastic.co/package/windows/3.5.0/

navnit-elastic pushed a commit to navnit-elastic/integrations that referenced this pull request Mar 2, 2026
…treams (elastic#17079)

windows: add support for event IDs 5137 and 5141 in forwarded data streams

Added ECS categorization for directory service object creation (5137) and deletion (5141) events. 
Includes new field mappings for AppCorrelationID, DSName, DSType, ObjectClass, ObjectDN, ObjectGUID, 
OpCorrelationID, and TreeDelete.

Test logs were generated from documentation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:windows Windows Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants