We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 87aab80 commit 6d3b2ccCopy full SHA for 6d3b2cc
CHANGELOG.next.md
@@ -22,6 +22,7 @@ Thanks, you're awesome :-) -->
22
* Added `rule` fields. #665
23
* Added default `text` analyzer as a multi-field to around 25 more fields. #680
24
* Added `registry.*` fieldset for the Windows registry. #673
25
+* Added `related.user` #694
26
27
#### Improvements
28
code/go/ecs/related.go
docs/field-details.asciidoc
@@ -3641,6 +3641,17 @@ type: ip
3641
3642
3643
3644
+| extended
3645
+
3646
+// ===============================================================
3647
3648
+| related.user
3649
+| All the user names seen on your event.
3650
3651
+type: keyword
3652
3653
3654
3655
| extended
3656
3657
// ===============================================================
generated/beats/fields.ecs.yml
@@ -2657,6 +2657,11 @@
2657
level: extended
2658
type: ip
2659
description: All of the IPs seen on your event.
2660
+ - name: user
2661
+ level: extended
2662
+ type: keyword
2663
+ ignore_above: 1024
2664
+ description: All the user names seen on your event.
2665
- name: rule
2666
title: Rule
2667
group: 2
generated/csv/fields.csv
@@ -350,6 +350,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Example,Description
350
1.4.0-dev,true,registry,registry.path,keyword,core,HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\Debugger,"Full path, including hive, key and value"
351
1.4.0-dev,true,registry,registry.value,keyword,core,Debugger,Name of the value written.
352
1.4.0-dev,true,related,related.ip,ip,extended,,All of the IPs seen on your event.
353
+1.4.0-dev,true,related,related.user,keyword,extended,,All the user names seen on your event.
354
1.4.0-dev,true,rule,rule.category,keyword,extended,Attempted Information Leak,Rule category
355
1.4.0-dev,true,rule,rule.description,keyword,extended,Block requests to public DNS over HTTPS / TLS protocols,Rule description
356
1.4.0-dev,true,rule,rule.id,keyword,extended,101,Rule ID
generated/ecs/ecs_flat.yml
@@ -4142,6 +4142,16 @@ related.ip:
4142
order: 0
4143
short: All of the IPs seen on your event.
4144
4145
+related.user:
4146
+ dashed_name: related-user
4147
4148
+ flat_name: related.user
4149
4150
4151
+ name: user
4152
+ order: 1
4153
+ short: All the user names seen on your event.
4154
4155
rule.category:
4156
dashed_name: rule-category
4157
description: A categorization value keyword used by the entity using the rule for
generated/ecs/ecs_nested.yml
@@ -4563,6 +4563,16 @@ related:
4563
4564
4565
4566
+ user:
4567
4568
4569
4570
4571
4572
4573
4574
4575
4576
4577
name: related
4578
prefix: related.
generated/elasticsearch/6/template.json
@@ -1664,6 +1664,10 @@
1664
"properties": {
1665
"ip": {
1666
"type": "ip"
1667
+ },
1668
+ "user": {
1669
+ "ignore_above": 1024,
1670
+ "type": "keyword"
1671
}
1672
1673
},
generated/elasticsearch/7/template.json
@@ -1663,6 +1663,10 @@
1663
schemas/related.yml
@@ -22,3 +22,9 @@
description: >
All of the IPs seen on your event.
29
+ description: >
30
+ All the user names seen on your event.
0 commit comments