-
Notifications
You must be signed in to change notification settings - Fork 392
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Winlog] Can't modify Dataset Name / event.dataset not conforming to ECS #5239
Conversation
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. The fact that Elastic Agent is always setting event.dataset
seems risky (and wasteful of storage) given that almost all integrations use a constant_keyword with static value.
Awesome 👌🏻 |
CI says the readme needs rebuilt. |
🌐 Coverage report
|
Package winlog - 1.12.1 containing this change is available at https://epr.elastic.co/search?package=winlog |
Thanks for running that for me and reviewing this! |
…astic#5239) The event.dataset is set to a constant_keyword which prevents anyone from changing the dataset in the custom windows integration.
What does this PR do?
Integration Impacted:
Custom Windows Event Logs integration
Screenshot of default Dataset name
Currently, the event.dataset is set to a constant_keyword which prevents anyone from changing the dataset in the custom windows integration. This should be a keyword to conform to ECS and allow anyone to modify the dataset in the integration as it is provided today.
If you change winlog.winlog to anything this will likely error.
Checklist
changelog.yml
file.Screenshots