File tree Expand file tree Collapse file tree
x-pack/plugins/security_solution/server/lib/telemetry Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -41,6 +41,7 @@ describe('TelemetryEventsSender', () => {
4141 version : '100' ,
4242 } ,
4343 file : {
44+ extension : '.exe' ,
4445 size : 3 ,
4546 created : 0 ,
4647 path : 'X' ,
@@ -72,6 +73,7 @@ describe('TelemetryEventsSender', () => {
7273 name : 'foo.exe' ,
7374 nope : 'nope' ,
7475 executable : null , // null fields are never allowlisted
76+ working_directory : '/some/usr/dir' ,
7577 } ,
7678 Target : {
7779 process : {
@@ -101,6 +103,7 @@ describe('TelemetryEventsSender', () => {
101103 version : '100' ,
102104 } ,
103105 file : {
106+ extension : '.exe' ,
104107 size : 3 ,
105108 created : 0 ,
106109 path : 'X' ,
@@ -126,6 +129,7 @@ describe('TelemetryEventsSender', () => {
126129 } ,
127130 process : {
128131 name : 'foo.exe' ,
132+ working_directory : '/some/usr/dir' ,
129133 } ,
130134 Target : {
131135 process : {
Original file line number Diff line number Diff line change @@ -307,6 +307,7 @@ const allowlistProcessFields: AllowlistFields = {
307307 } ,
308308 } ,
309309 thread : true ,
310+ working_directory : true ,
310311} ;
311312
312313// Allow list for event-related fields, which can also be nested under events[]
@@ -322,6 +323,7 @@ const allowlistBaseEventFields: AllowlistFields = {
322323 } ,
323324 event : true ,
324325 file : {
326+ extension : true ,
325327 name : true ,
326328 path : true ,
327329 size : true ,
You can’t perform that action at this time.
0 commit comments