Skip to content

Commit dee93b2

Browse files
author
Andrew Stucki
authored
Cherry-pick #20138 to 7.x: [Filebeat] Update crowdstrike module (#20176)
* [Filebeat] Update crowdstrike module (#20138) * Update crowdstrike module (cherry picked from commit 5e9a3a5) * Fix up changelog
1 parent b80fc78 commit dee93b2

File tree

14 files changed

+1915
-240
lines changed

14 files changed

+1915
-240
lines changed

CHANGELOG.next.asciidoc

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -252,6 +252,7 @@ field. You can revert this change by configuring tags for the module and omittin
252252
- Fix Filebeat OOMs on very long lines {issue}19500[19500], {pull}19552[19552]
253253
- Fix s3 input parsing json file without expand_event_list_from_field. {issue}19902[19902] {pull}19962[19962]
254254
- Ignore missing in Zeek module when dropping unecessary fields. {pull}19984[19984]
255+
- Fix millisecond timestamp normalization issues in CrowdStrike module {issue}20035[20035], {pull}20138[20138]
255256

256257
*Heartbeat*
257258

@@ -565,6 +566,8 @@ field. You can revert this change by configuring tags for the module and omittin
565566
- Add experimental dataset sonicwall/firewall for Sonicwall Firewalls logs {pull}19713[19713]
566567
- Add experimental dataset squid/log for Squid Proxy Server logs {pull}19713[19713]
567568
- Add experimental dataset zscaler/zia for Zscaler Internet Access logs {pull}19713[19713]
569+
- Add event.ingested for CrowdStrike module {pull}20138[20138]
570+
- Add support for additional fields and FirewallMatchEvent type events in CrowdStrike module {pull}20138[20138]
568571

569572
*Heartbeat*
570573

0 commit comments

Comments
 (0)