Skip to content

system package using invalid field values according to ECS  #3051

@jsoriano

Description

@jsoriano
[0] parsing field value failed: field "event.type"'s value "authentication_success" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)
[0] parsing field value failed: field "event.type"'s value "authentication_failure" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)

"authentication_failure" => "denied"? or "access", and use "event.outcome" to indicate the failure?

Part of #3016

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions