-
Notifications
You must be signed in to change notification settings - Fork 19
Mitigation policies #319
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Mitigation policies #319
Conversation
|
/test |
|
@elastic/security-onboarding-and-lifecycle-mgt could anyone review this pr if anyone got any spare cycles? |
|
@elastic/security-onboarding-and-lifecycle-mgt can I get some review of this pr or is it code freezing time? Thanks in advance! |
|
@Trinity2019 - apologies for the late review. This looks good to me. We were working out some issues with the This change looks good to me and is purely additive, so it won't cause any mapping collisions. |
|
Thanks all the reviewers! No worries about delay, all good :) |
|
Package endpoint - 8.7.0 containing this change is available at https://epr.elastic.co/search?package=endpoint |
Change Summary
Add
mitigation_policiesto Windows process creation events.Sample values
Sample document:
Here's a sample process event document.
Release Target
8.7.0
For mapping changes:
makeafter making the schema changes, and committed all changes