Skip to content

Conversation

@AsuNa-jp
Copy link
Contributor

@AsuNa-jp AsuNa-jp commented Jun 23, 2025

Change Summary

This PR adds the following fields to logoff security events custom documentation.

  • process.Ext.protection
  • process.Ext.token.integrity_level_name
  • process.command_line
  • process.name
  • process.parent.executable
  • process.pid

Reference: https://github.com/elastic/endpoint-dev/pull/16550

Release Target

8.19/9.1

Q/A

For mapping changes:

  • I ran make after making the schema changes, and committed all changes

@AsuNa-jp AsuNa-jp self-assigned this Jun 23, 2025
@AsuNa-jp AsuNa-jp marked this pull request as ready for review June 23, 2025 08:30
@AsuNa-jp AsuNa-jp requested a review from a team as a code owner June 23, 2025 08:30
@AsuNa-jp AsuNa-jp merged commit 9e5557a into main Jun 23, 2025
4 checks passed
@pzl pzl deleted the update_security_event_custom_documentation branch June 24, 2025 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants