Extend user.name mapping to Windows Integration Package#8289
Extend user.name mapping to Windows Integration Package#8289efd6 merged 15 commits intoelastic:mainfrom ChriZzn:main
Conversation
Adding EventID 4662 and 5136, to use the winlog.event_data.SubjectUserName as user.name and related.user
|
Pinging @elastic/elastic-agent (Team:Elastic-Agent) |
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
leehinman
left a comment
There was a problem hiding this comment.
you will need to update the version number in packages/windows/manifest.yml as well.
packages/windows/data_stream/forwarded/elasticsearch/ingest_pipeline/security.yml
Show resolved
Hide resolved
|
Any Updates on this? |
|
Sorry this was dropped. Please fix the conflict in the system changelog. |
|
Hello, should be resolved now, Regards |
|
/test |
🌐 Coverage report
|
|
Please apply the this patch file and then resolve the conflicts, 0001-add-tests.patch. |
|
💚 CLA has been signed |
|
Hi i applied the patch and resolved the conflicts.... |
|
The author you've used to apply the patch is making the CLA checker unhappy. Would you please sign the CLA with that name/email address as well? |
Hi, should be signed now with username 'cw', Regards |
|
It will need to match exactly, including the email address. |
|
so
Resigned the CLA, please DM me the email/username combo if there are still Problems |
|
/test |
|
Package system - 1.48.0 containing this change is available at https://epr.elastic.co/search?package=system |
|
Package windows - 1.42.0 containing this change is available at https://epr.elastic.co/search?package=windows |
Proposed commit message
Adding EventID 4662 and 5136, to use the 'winlog.event_data.SubjectUserName' as user.name and related.user
Checklist
changelog.ymlfile.