Skip to content

Commit 6d3b2cc

Browse files
jannitenMathieu Martin
authored andcommitted
Added related.user field (#694)
1 parent 87aab80 commit 6d3b2cc

File tree

10 files changed

+55
-0
lines changed

10 files changed

+55
-0
lines changed

CHANGELOG.next.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,7 @@ Thanks, you're awesome :-) -->
2222
* Added `rule` fields. #665
2323
* Added default `text` analyzer as a multi-field to around 25 more fields. #680
2424
* Added `registry.*` fieldset for the Windows registry. #673
25+
* Added `related.user` #694
2526

2627
#### Improvements
2728

code/go/ecs/related.go

Lines changed: 3 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

docs/field-details.asciidoc

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3641,6 +3641,17 @@ type: ip
36413641

36423642

36433643

3644+
| extended
3645+
3646+
// ===============================================================
3647+
3648+
| related.user
3649+
| All the user names seen on your event.
3650+
3651+
type: keyword
3652+
3653+
3654+
36443655
| extended
36453656

36463657
// ===============================================================

generated/beats/fields.ecs.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2657,6 +2657,11 @@
26572657
level: extended
26582658
type: ip
26592659
description: All of the IPs seen on your event.
2660+
- name: user
2661+
level: extended
2662+
type: keyword
2663+
ignore_above: 1024
2664+
description: All the user names seen on your event.
26602665
- name: rule
26612666
title: Rule
26622667
group: 2

generated/csv/fields.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,6 +350,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
350350
1.4.0-dev,true,registry,registry.path,keyword,core,HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\Debugger,"Full path, including hive, key and value"
351351
1.4.0-dev,true,registry,registry.value,keyword,core,Debugger,Name of the value written.
352352
1.4.0-dev,true,related,related.ip,ip,extended,,All of the IPs seen on your event.
353+
1.4.0-dev,true,related,related.user,keyword,extended,,All the user names seen on your event.
353354
1.4.0-dev,true,rule,rule.category,keyword,extended,Attempted Information Leak,Rule category
354355
1.4.0-dev,true,rule,rule.description,keyword,extended,Block requests to public DNS over HTTPS / TLS protocols,Rule description
355356
1.4.0-dev,true,rule,rule.id,keyword,extended,101,Rule ID

generated/ecs/ecs_flat.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4142,6 +4142,16 @@ related.ip:
41424142
order: 0
41434143
short: All of the IPs seen on your event.
41444144
type: ip
4145+
related.user:
4146+
dashed_name: related-user
4147+
description: All the user names seen on your event.
4148+
flat_name: related.user
4149+
ignore_above: 1024
4150+
level: extended
4151+
name: user
4152+
order: 1
4153+
short: All the user names seen on your event.
4154+
type: keyword
41454155
rule.category:
41464156
dashed_name: rule-category
41474157
description: A categorization value keyword used by the entity using the rule for

generated/ecs/ecs_nested.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4563,6 +4563,16 @@ related:
45634563
order: 0
45644564
short: All of the IPs seen on your event.
45654565
type: ip
4566+
user:
4567+
dashed_name: related-user
4568+
description: All the user names seen on your event.
4569+
flat_name: related.user
4570+
ignore_above: 1024
4571+
level: extended
4572+
name: user
4573+
order: 1
4574+
short: All the user names seen on your event.
4575+
type: keyword
45664576
group: 2
45674577
name: related
45684578
prefix: related.

generated/elasticsearch/6/template.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1664,6 +1664,10 @@
16641664
"properties": {
16651665
"ip": {
16661666
"type": "ip"
1667+
},
1668+
"user": {
1669+
"ignore_above": 1024,
1670+
"type": "keyword"
16671671
}
16681672
}
16691673
},

generated/elasticsearch/7/template.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1663,6 +1663,10 @@
16631663
"properties": {
16641664
"ip": {
16651665
"type": "ip"
1666+
},
1667+
"user": {
1668+
"ignore_above": 1024,
1669+
"type": "keyword"
16661670
}
16671671
}
16681672
},

schemas/related.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,3 +22,9 @@
2222
type: ip
2323
description: >
2424
All of the IPs seen on your event.
25+
26+
- name: user
27+
level: extended
28+
type: keyword
29+
description: >
30+
All the user names seen on your event.

0 commit comments

Comments
 (0)