You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For Detection compatibility purposes, we need to adjust and add some fields to the integrations shipped process creation logs.
System Integration:
process.name.caseless
process.executable.caseless
process.args_count
Windows Integration:
process.name.caseless
process.executable.caseless
process.args_count (Sysmon logs already have these, needs to be added to win forwarded logs)
In Sysmon and in the winevent logs, we don't have a caseless field as we do in Elastic Defend, which prevents them from working with rules that use KQL, like new_terms.
The text was updated successfully, but these errors were encountered:
They will probably be in 8.16, as this is not blocking any work and is an enhancement, I closed #9850 and will wait for the ECS release to modify the related rules.
For Detection compatibility purposes, we need to adjust and add some fields to the integrations shipped process creation logs.
System Integration:
Windows Integration:
In Sysmon and in the winevent logs, we don't have a caseless field as we do in Elastic Defend, which prevents them from working with rules that use KQL, like new_terms.
The text was updated successfully, but these errors were encountered: