Skip to content

[SIEM] Update TLS tables for ECS 1.4+ #60026

@andrewkroh

Description

@andrewkroh

The TLS tables in the SIEM UI we first created before there were any TLS fields defined in Elastic Common Schema (ECS). Since ECS 1.4 the TLS fields have been added. The Beat data sources are being updated to produce ECS conforming TLS events. Now the queries executed by the UI need to be updated.

One open question is whether the tables should remain backward-compatible with the earlier Packetbeat format for some time period.

See also:

Metadata

Metadata

Assignees

No one assigned

    Labels

    Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:SIEM

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions