-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ETW Threat-Intelligence API events #427
Conversation
@jdu2600 , would it be possible for you pull in |
…to etwti_events
I added an example document. Tests are passing. Ready for review. |
Package endpoint - 8.11.0 containing this change is available at https://epr.elastic.co/search?package=endpoint |
@ferullo - Is there anything else that I should do on the documentation front? |
If you're referring to custom documentation, no don't worry about it. I'll follow up and add those files after 8.11 is branched. |
Change Summary
This PR adds multiple new API event variants, including new call_stack fields.
Sample values for new fields
Sample document
Release Target
8.11.0
Q/A
make
after making the schema changes, and committed all changes