Skip to content

Windows/System security: process.args_count (4688), 5136 event.reason & ObjectDN#17921

Merged
marc-gr merged 10 commits intoelastic:mainfrom
marc-gr:windows-system-security-4688-5136
Mar 30, 2026
Merged

Windows/System security: process.args_count (4688), 5136 event.reason & ObjectDN#17921
marc-gr merged 10 commits intoelastic:mainfrom
marc-gr:windows-system-security-4688-5136

Conversation

@marc-gr
Copy link
Copy Markdown
Contributor

@marc-gr marc-gr commented Mar 20, 2026

Summary

Enhancements for Windows Security events in windows forwarded and system security data streams (pipelines kept in sync).

Changes

Versions

  • windows 3.6.1 → 3.7.0
  • system 2.13.0 → 2.14.0

Testing

elastic-package test pipeline -v -C packages/windows -d forwarded
elastic-package test pipeline -v -C packages/system -d security

Closes #14767
Closes #15308
Closes #16965

…ectDN

- Add process.args_count for event 4688 (elastic#14767)
- Map OperationType to event.reason for event 5136 (elastic#15308)
- Parse ObjectDN for 5136 into user.target/group/host by ObjectClass (elastic#16965)

Keep windows.forwarded and system.security pipelines in sync.
@marc-gr marc-gr requested review from a team as code owners March 20, 2026 08:43
@marc-gr marc-gr added Integration:windows Windows Integration:system System Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] labels Mar 20, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

@marc-gr marc-gr enabled auto-merge (squash) March 20, 2026 09:32
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

elastic-vault-github-plugin-prod bot commented Mar 20, 2026

🚀 Benchmarks report

Package windows 👍(5) 💚(2) 💔(3)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
powershell_operational 2873.56 1349.89 -1523.67 (-53.02%) 💔
applocker_packaged_app_deployment 11627.91 7352.94 -4274.97 (-36.76%) 💔
applocker_packaged_app_execution 11764.71 8196.72 -3567.99 (-30.33%) 💔

To see the full report comment with /test benchmark fullreport

@pierrehilbert pierrehilbert added the Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] label Mar 20, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

@marc-gr marc-gr disabled auto-merge March 23, 2026 15:34
marc-gr added 2 commits March 30, 2026 15:37
…og from elastic#17931

- system 2.15.0, windows 3.8.0
- Changelog: 17921 entries under new versions; 17931 remains on 2.14.0 / 3.7.0
@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

History

@marc-gr marc-gr merged commit 0a5f0a0 into elastic:main Mar 30, 2026
10 checks passed
@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

Package system - 2.15.0 containing this change is available at https://epr.elastic.co/package/system/2.15.0/

@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

Package windows - 3.8.0 containing this change is available at https://epr.elastic.co/package/windows/3.8.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:system System Integration:windows Windows Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

5 participants