You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The network_endpoint object currently has enrichment metadata for Geo Location but is missing another common enrichment source: Autonomous System information which can be enriched from free sources like GeoLite2 and many paid as well. These fields are useful for threat hunting in network logs and attributing IPs to their owners and would be helpful in the common schema.
The network_endpoint object currently has enrichment metadata for Geo Location but is missing another common enrichment source: Autonomous System information which can be enriched from free sources like GeoLite2 and many paid as well. These fields are useful for threat hunting in network logs and attributing IPs to their owners and would be helpful in the common schema.
These exist in ECS as well.
The text was updated successfully, but these errors were encountered: