Hi,
Just an FYI you might want to add a vulnerability.published date field to ECS.
This is because the vulnerability might be published several years previous, so we'd still want to set @timestamp and event.created to the current date time or when the vulnerability was identified. The vulnerability.published field would be the date the vulnerability was first reported. Users will want to filter on when the vulnerability was identified on their network.
Thanks,