Closed
Description
openedon Jun 5, 2019
As per ECS the network.direction
values should be inbound
or outbound
or unknown
.
https://github.com/elastic/ecs/blob/v1.0.1/schemas/network.yml#L88-L92
But the auditd
modules uses incoming
and outgoing
for audit events that include a socket message.
beats/vendor/github.com/elastic/go-libaudit/aucoalesce/coalesce.go
Lines 112 to 120 in 6c55de4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment