@@ -14,7 +14,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
14
14
1.5.0-dev,true,client,client.address,keyword,extended,,Client network address.
15
15
1.5.0-dev,true,client,client.as.number,long,extended,15169,Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet.
16
16
1.5.0-dev,true,client,client.as.organization.name,keyword,extended,Google LLC,Organization name.
17
- 1.5.0-dev,true,client,as.organization.name.text,text,extended,Google LLC,Organization name.
17
+ 1.5.0-dev,true,client,client. as.organization.name.text,text,extended,Google LLC,Organization name.
18
18
1.5.0-dev,true,client,client.bytes,long,core,184,Bytes sent from the client to the server.
19
19
1.5.0-dev,true,client,client.domain,keyword,core,,Client domain.
20
20
1.5.0-dev,true,client,client.geo.city_name,keyword,core,Montreal,City name.
@@ -36,14 +36,14 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
36
36
1.5.0-dev,true,client,client.user.domain,keyword,extended,,Name of the directory the user is a member of.
37
37
1.5.0-dev,true,client,client.user.email,keyword,extended,,User email address.
38
38
1.5.0-dev,true,client,client.user.full_name,keyword,extended,Albert Einstein,"User's full name, if available."
39
- 1.5.0-dev,true,client,user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
39
+ 1.5.0-dev,true,client,client. user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
40
40
1.5.0-dev,true,client,client.user.group.domain,keyword,extended,,Name of the directory the group is a member of.
41
41
1.5.0-dev,true,client,client.user.group.id,keyword,extended,,Unique identifier for the group on the system/platform.
42
42
1.5.0-dev,true,client,client.user.group.name,keyword,extended,,Name of the group.
43
43
1.5.0-dev,true,client,client.user.hash,keyword,extended,,Unique user hash to correlate information for a user in anonymized form.
44
44
1.5.0-dev,true,client,client.user.id,keyword,core,,One or multiple unique identifiers of the user.
45
45
1.5.0-dev,true,client,client.user.name,keyword,core,albert,Short name or login of the user.
46
- 1.5.0-dev,true,client,user.name.text,text,core,albert,Short name or login of the user.
46
+ 1.5.0-dev,true,client,client. user.name.text,text,core,albert,Short name or login of the user.
47
47
1.5.0-dev,true,cloud,cloud.account.id,keyword,extended,666777888999,The cloud account or organization id.
48
48
1.5.0-dev,true,cloud,cloud.availability_zone,keyword,extended,us-east-1c,Availability zone in which this host is running.
49
49
1.5.0-dev,true,cloud,cloud.instance.id,keyword,extended,i-1234567890abcdef0,Instance ID of the host machine.
@@ -60,7 +60,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
60
60
1.5.0-dev,true,destination,destination.address,keyword,extended,,Destination network address.
61
61
1.5.0-dev,true,destination,destination.as.number,long,extended,15169,Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet.
62
62
1.5.0-dev,true,destination,destination.as.organization.name,keyword,extended,Google LLC,Organization name.
63
- 1.5.0-dev,true,destination,as.organization.name.text,text,extended,Google LLC,Organization name.
63
+ 1.5.0-dev,true,destination,destination. as.organization.name.text,text,extended,Google LLC,Organization name.
64
64
1.5.0-dev,true,destination,destination.bytes,long,core,184,Bytes sent from the destination to the source.
65
65
1.5.0-dev,true,destination,destination.domain,keyword,core,,Destination domain.
66
66
1.5.0-dev,true,destination,destination.geo.city_name,keyword,core,Montreal,City name.
@@ -82,14 +82,14 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
82
82
1.5.0-dev,true,destination,destination.user.domain,keyword,extended,,Name of the directory the user is a member of.
83
83
1.5.0-dev,true,destination,destination.user.email,keyword,extended,,User email address.
84
84
1.5.0-dev,true,destination,destination.user.full_name,keyword,extended,Albert Einstein,"User's full name, if available."
85
- 1.5.0-dev,true,destination,user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
85
+ 1.5.0-dev,true,destination,destination. user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
86
86
1.5.0-dev,true,destination,destination.user.group.domain,keyword,extended,,Name of the directory the group is a member of.
87
87
1.5.0-dev,true,destination,destination.user.group.id,keyword,extended,,Unique identifier for the group on the system/platform.
88
88
1.5.0-dev,true,destination,destination.user.group.name,keyword,extended,,Name of the group.
89
89
1.5.0-dev,true,destination,destination.user.hash,keyword,extended,,Unique user hash to correlate information for a user in anonymized form.
90
90
1.5.0-dev,true,destination,destination.user.id,keyword,core,,One or multiple unique identifiers of the user.
91
91
1.5.0-dev,true,destination,destination.user.name,keyword,core,albert,Short name or login of the user.
92
- 1.5.0-dev,true,destination,user.name.text,text,core,albert,Short name or login of the user.
92
+ 1.5.0-dev,true,destination,destination. user.name.text,text,core,albert,Short name or login of the user.
93
93
1.5.0-dev,true,dns,dns.answers,object,extended,,Array of DNS answers.
94
94
1.5.0-dev,true,dns,dns.answers.class,keyword,extended,IN,The class of DNS data contained in this resource record.
95
95
1.5.0-dev,true,dns,dns.answers.data,keyword,extended,10.10.10.10,The data describing the resource.
@@ -195,25 +195,25 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
195
195
1.5.0-dev,true,host,host.name,keyword,core,,Name of the host.
196
196
1.5.0-dev,true,host,host.os.family,keyword,extended,debian,"OS family (such as redhat, debian, freebsd, windows)."
197
197
1.5.0-dev,true,host,host.os.full,keyword,extended,Mac OS Mojave,"Operating system name, including the version or code name."
198
- 1.5.0-dev,true,host,os.full.text,text,extended,Mac OS Mojave,"Operating system name, including the version or code name."
198
+ 1.5.0-dev,true,host,host. os.full.text,text,extended,Mac OS Mojave,"Operating system name, including the version or code name."
199
199
1.5.0-dev,true,host,host.os.kernel,keyword,extended,4.4.0-112-generic,Operating system kernel version as a raw string.
200
200
1.5.0-dev,true,host,host.os.name,keyword,extended,Mac OS X,"Operating system name, without the version."
201
- 1.5.0-dev,true,host,os.name.text,text,extended,Mac OS X,"Operating system name, without the version."
201
+ 1.5.0-dev,true,host,host. os.name.text,text,extended,Mac OS X,"Operating system name, without the version."
202
202
1.5.0-dev,true,host,host.os.platform,keyword,extended,darwin,"Operating system platform (such centos, ubuntu, windows)."
203
203
1.5.0-dev,true,host,host.os.version,keyword,extended,10.14.1,Operating system version as a raw string.
204
204
1.5.0-dev,true,host,host.type,keyword,core,,Type of host.
205
205
1.5.0-dev,true,host,host.uptime,long,extended,1325,Seconds the host has been up.
206
206
1.5.0-dev,true,host,host.user.domain,keyword,extended,,Name of the directory the user is a member of.
207
207
1.5.0-dev,true,host,host.user.email,keyword,extended,,User email address.
208
208
1.5.0-dev,true,host,host.user.full_name,keyword,extended,Albert Einstein,"User's full name, if available."
209
- 1.5.0-dev,true,host,user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
209
+ 1.5.0-dev,true,host,host. user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
210
210
1.5.0-dev,true,host,host.user.group.domain,keyword,extended,,Name of the directory the group is a member of.
211
211
1.5.0-dev,true,host,host.user.group.id,keyword,extended,,Unique identifier for the group on the system/platform.
212
212
1.5.0-dev,true,host,host.user.group.name,keyword,extended,,Name of the group.
213
213
1.5.0-dev,true,host,host.user.hash,keyword,extended,,Unique user hash to correlate information for a user in anonymized form.
214
214
1.5.0-dev,true,host,host.user.id,keyword,core,,One or multiple unique identifiers of the user.
215
215
1.5.0-dev,true,host,host.user.name,keyword,core,albert,Short name or login of the user.
216
- 1.5.0-dev,true,host,user.name.text,text,core,albert,Short name or login of the user.
216
+ 1.5.0-dev,true,host,host. user.name.text,text,core,albert,Short name or login of the user.
217
217
1.5.0-dev,true,http,http.request.body.bytes,long,extended,887,Size in bytes of the request body.
218
218
1.5.0-dev,true,http,http.request.body.content,keyword,extended,Hello world,The full HTTP request body.
219
219
1.5.0-dev,true,http,http.request.body.content.text,text,extended,Hello world,The full HTTP request body.
@@ -263,10 +263,10 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
263
263
1.5.0-dev,true,observer,observer.name,keyword,extended,1_proxySG,Custom name of the observer.
264
264
1.5.0-dev,true,observer,observer.os.family,keyword,extended,debian,"OS family (such as redhat, debian, freebsd, windows)."
265
265
1.5.0-dev,true,observer,observer.os.full,keyword,extended,Mac OS Mojave,"Operating system name, including the version or code name."
266
- 1.5.0-dev,true,observer,os.full.text,text,extended,Mac OS Mojave,"Operating system name, including the version or code name."
266
+ 1.5.0-dev,true,observer,observer. os.full.text,text,extended,Mac OS Mojave,"Operating system name, including the version or code name."
267
267
1.5.0-dev,true,observer,observer.os.kernel,keyword,extended,4.4.0-112-generic,Operating system kernel version as a raw string.
268
268
1.5.0-dev,true,observer,observer.os.name,keyword,extended,Mac OS X,"Operating system name, without the version."
269
- 1.5.0-dev,true,observer,os.name.text,text,extended,Mac OS X,"Operating system name, without the version."
269
+ 1.5.0-dev,true,observer,observer. os.name.text,text,extended,Mac OS X,"Operating system name, without the version."
270
270
1.5.0-dev,true,observer,observer.os.platform,keyword,extended,darwin,"Operating system platform (such centos, ubuntu, windows)."
271
271
1.5.0-dev,true,observer,observer.os.version,keyword,extended,10.14.1,Operating system version as a raw string.
272
272
1.5.0-dev,true,observer,observer.product,keyword,extended,s200,The product name of the observer.
@@ -362,7 +362,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
362
362
1.5.0-dev,true,server,server.address,keyword,extended,,Server network address.
363
363
1.5.0-dev,true,server,server.as.number,long,extended,15169,Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet.
364
364
1.5.0-dev,true,server,server.as.organization.name,keyword,extended,Google LLC,Organization name.
365
- 1.5.0-dev,true,server,as.organization.name.text,text,extended,Google LLC,Organization name.
365
+ 1.5.0-dev,true,server,server. as.organization.name.text,text,extended,Google LLC,Organization name.
366
366
1.5.0-dev,true,server,server.bytes,long,core,184,Bytes sent from the server to the client.
367
367
1.5.0-dev,true,server,server.domain,keyword,core,,Server domain.
368
368
1.5.0-dev,true,server,server.geo.city_name,keyword,core,Montreal,City name.
@@ -384,14 +384,14 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
384
384
1.5.0-dev,true,server,server.user.domain,keyword,extended,,Name of the directory the user is a member of.
385
385
1.5.0-dev,true,server,server.user.email,keyword,extended,,User email address.
386
386
1.5.0-dev,true,server,server.user.full_name,keyword,extended,Albert Einstein,"User's full name, if available."
387
- 1.5.0-dev,true,server,user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
387
+ 1.5.0-dev,true,server,server. user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
388
388
1.5.0-dev,true,server,server.user.group.domain,keyword,extended,,Name of the directory the group is a member of.
389
389
1.5.0-dev,true,server,server.user.group.id,keyword,extended,,Unique identifier for the group on the system/platform.
390
390
1.5.0-dev,true,server,server.user.group.name,keyword,extended,,Name of the group.
391
391
1.5.0-dev,true,server,server.user.hash,keyword,extended,,Unique user hash to correlate information for a user in anonymized form.
392
392
1.5.0-dev,true,server,server.user.id,keyword,core,,One or multiple unique identifiers of the user.
393
393
1.5.0-dev,true,server,server.user.name,keyword,core,albert,Short name or login of the user.
394
- 1.5.0-dev,true,server,user.name.text,text,core,albert,Short name or login of the user.
394
+ 1.5.0-dev,true,server,server. user.name.text,text,core,albert,Short name or login of the user.
395
395
1.5.0-dev,true,service,service.ephemeral_id,keyword,extended,8a4f500f,Ephemeral identifier of this service.
396
396
1.5.0-dev,true,service,service.id,keyword,core,d37e5ebfe0ae6c4972dbe9f0174a1637bb8247f6,Unique identifier of the running service.
397
397
1.5.0-dev,true,service,service.name,keyword,core,elasticsearch-metrics,Name of the service.
@@ -402,7 +402,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
402
402
1.5.0-dev,true,source,source.address,keyword,extended,,Source network address.
403
403
1.5.0-dev,true,source,source.as.number,long,extended,15169,Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet.
404
404
1.5.0-dev,true,source,source.as.organization.name,keyword,extended,Google LLC,Organization name.
405
- 1.5.0-dev,true,source,as.organization.name.text,text,extended,Google LLC,Organization name.
405
+ 1.5.0-dev,true,source,source. as.organization.name.text,text,extended,Google LLC,Organization name.
406
406
1.5.0-dev,true,source,source.bytes,long,core,184,Bytes sent from the source to the destination.
407
407
1.5.0-dev,true,source,source.domain,keyword,core,,Source domain.
408
408
1.5.0-dev,true,source,source.geo.city_name,keyword,core,Montreal,City name.
@@ -424,14 +424,14 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
424
424
1.5.0-dev,true,source,source.user.domain,keyword,extended,,Name of the directory the user is a member of.
425
425
1.5.0-dev,true,source,source.user.email,keyword,extended,,User email address.
426
426
1.5.0-dev,true,source,source.user.full_name,keyword,extended,Albert Einstein,"User's full name, if available."
427
- 1.5.0-dev,true,source,user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
427
+ 1.5.0-dev,true,source,source. user.full_name.text,text,extended,Albert Einstein,"User's full name, if available."
428
428
1.5.0-dev,true,source,source.user.group.domain,keyword,extended,,Name of the directory the group is a member of.
429
429
1.5.0-dev,true,source,source.user.group.id,keyword,extended,,Unique identifier for the group on the system/platform.
430
430
1.5.0-dev,true,source,source.user.group.name,keyword,extended,,Name of the group.
431
431
1.5.0-dev,true,source,source.user.hash,keyword,extended,,Unique user hash to correlate information for a user in anonymized form.
432
432
1.5.0-dev,true,source,source.user.id,keyword,core,,One or multiple unique identifiers of the user.
433
433
1.5.0-dev,true,source,source.user.name,keyword,core,albert,Short name or login of the user.
434
- 1.5.0-dev,true,source,user.name.text,text,core,albert,Short name or login of the user.
434
+ 1.5.0-dev,true,source,source. user.name.text,text,core,albert,Short name or login of the user.
435
435
1.5.0-dev,true,threat,threat.framework,keyword,extended,MITRE ATT&CK,Threat classification framework.
436
436
1.5.0-dev,true,threat,threat.tactic.id,keyword,extended,TA0040,Threat tactic id.
437
437
1.5.0-dev,true,threat,threat.tactic.name,keyword,extended,impact,Threat tactic.
@@ -503,10 +503,10 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
503
503
1.5.0-dev,true,user_agent,user_agent.original.text,text,extended,"Mozilla/5.0 (iPhone; CPU iPhone OS 12_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0 Mobile/15E148 Safari/604.1",Unparsed user_agent string.
504
504
1.5.0-dev,true,user_agent,user_agent.os.family,keyword,extended,debian,"OS family (such as redhat, debian, freebsd, windows)."
505
505
1.5.0-dev,true,user_agent,user_agent.os.full,keyword,extended,Mac OS Mojave,"Operating system name, including the version or code name."
506
- 1.5.0-dev,true,user_agent,os.full.text,text,extended,Mac OS Mojave,"Operating system name, including the version or code name."
506
+ 1.5.0-dev,true,user_agent,user_agent. os.full.text,text,extended,Mac OS Mojave,"Operating system name, including the version or code name."
507
507
1.5.0-dev,true,user_agent,user_agent.os.kernel,keyword,extended,4.4.0-112-generic,Operating system kernel version as a raw string.
508
508
1.5.0-dev,true,user_agent,user_agent.os.name,keyword,extended,Mac OS X,"Operating system name, without the version."
509
- 1.5.0-dev,true,user_agent,os.name.text,text,extended,Mac OS X,"Operating system name, without the version."
509
+ 1.5.0-dev,true,user_agent,user_agent. os.name.text,text,extended,Mac OS X,"Operating system name, without the version."
510
510
1.5.0-dev,true,user_agent,user_agent.os.platform,keyword,extended,darwin,"Operating system platform (such centos, ubuntu, windows)."
511
511
1.5.0-dev,true,user_agent,user_agent.os.version,keyword,extended,10.14.1,Operating system version as a raw string.
512
512
1.5.0-dev,true,user_agent,user_agent.version,keyword,extended,12.0,Version of the user agent.
0 commit comments