Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Winlogbeat: Fill event.provider #13937

Merged
merged 5 commits into from
Oct 12, 2019
Merged

Conversation

cwurm
Copy link
Contributor

@cwurm cwurm commented Oct 7, 2019

Fills the ECS field event.provider with the provider name that is currently in winlog.provider_name.

Example values:

  • Microsoft-Windows-Security-Auditing
  • Microsoft-Windows-Sysmon

This will allow distinguishing event.code values from different logs (e.g. Security Auditing vs. Sysmon).

/fyi @webmat

@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

Copy link
Member

@andrewkroh andrewkroh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Can you please add an entry in the changelog for this.

@cwurm cwurm merged commit be69f91 into elastic:master Oct 12, 2019
@cwurm cwurm deleted the winlogbeat_event_provider branch October 12, 2019 20:48
@urso urso added the v7.5.0 label Oct 22, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants