Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat] Upgrade misp module to ECS 1.4 #16026

Closed
1 task
leehinman opened this issue Feb 3, 2020 · 1 comment · Fixed by #17344
Closed
1 task

[Filebeat] Upgrade misp module to ECS 1.4 #16026

leehinman opened this issue Feb 3, 2020 · 1 comment · Fixed by #17344
Assignees

Comments

@leehinman
Copy link
Contributor

leehinman commented Feb 3, 2020

Filesets

  • threat

add ECS threat fields

@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@leehinman leehinman changed the title [Filebeat] Update misp/threat fileset to support ECS 1.4 fields [Filebeat] Upgrade misp module to ECS 1.4 Feb 6, 2020
@leehinman leehinman self-assigned this Mar 27, 2020
leehinman added a commit to leehinman/beats that referenced this issue Mar 30, 2020
- event.id
- event.kind
- registry.key if indicator type regkey
- rule.category
- rule.description
- rule.id
- rule.uuid
- user.name if indicator type github-username

Closes elastic#16026
leehinman added a commit that referenced this issue Apr 20, 2020
- event.id
- event.kind
- registry.key if indicator type regkey
- rule.category
- rule.description
- rule.id
- rule.uuid
- user.name if indicator type github-username

Closes #16026
leehinman added a commit to leehinman/beats that referenced this issue Apr 20, 2020
)

- event.id
- event.kind
- registry.key if indicator type regkey
- rule.category
- rule.description
- rule.id
- rule.uuid
- user.name if indicator type github-username

Closes elastic#16026

(cherry picked from commit fee1f15)
leehinman added a commit that referenced this issue Apr 21, 2020
…17845)

- event.id
- event.kind
- registry.key if indicator type regkey
- rule.category
- rule.description
- rule.id
- rule.uuid
- user.name if indicator type github-username

Closes #16026

(cherry picked from commit fee1f15)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants