-
Notifications
You must be signed in to change notification settings - Fork 474
[Enhancement] Update winlog.event_data.AttributeValue mappings #9515
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
/test |
cc @jamiehynds |
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
@marc-gr would you mind helping with the review for this enhancement to unblock the TRADE team from building some new detection rules? |
/test |
@w0rk3r the README needs to be updated. It should be alright after commiting the changes after |
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
History
cc @w0rk3r |
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for fixing the build error.
Looks good!
Package system - 1.57.0 containing this change is available at https://epr.elastic.co/search?package=system |
Summary
Attempts to resolve #7381
Proposed commit message
Adjusts the
ignore_above
parameter to make Active Directory DACLs searchable, adds a wildcard multi-field towinlog.event_data.AttributeValue
.Checklist
changelog.yml
file.Related issues
#7381