Skip to content

Commit 5b93eff

Browse files
authored
add more custom documentation fields on windows (#424)
1 parent f057d48 commit 5b93eff

File tree

4 files changed

+12
-0
lines changed

4 files changed

+12
-0
lines changed

custom_documentation/doc/endpoint/file/windows/windows_file_rename.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ This event is generated when a file is renamed.
1010
| Field |
1111
|---|
1212
| @timestamp |
13+
| Effective_process.entity_id |
14+
| Effective_process.executable |
15+
| Effective_process.name |
16+
| Effective_process.pid |
1317
| agent.id |
1418
| agent.type |
1519
| agent.version |

custom_documentation/doc/endpoint/metrics/metrics.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -118,6 +118,8 @@ This is an internal state management document that includes metrics on Endpoint'
118118
| Endpoint.metrics.system_impact.registry_events.week_ms |
119119
| Endpoint.metrics.system_impact.threat_intelligence_events.week_idle_ms |
120120
| Endpoint.metrics.system_impact.threat_intelligence_events.week_ms |
121+
| Endpoint.metrics.system_impact.win32k_events.week_idle_ms |
122+
| Endpoint.metrics.system_impact.win32k_events.week_ms |
121123
| Endpoint.metrics.threads.cpu.mean |
122124
| Endpoint.metrics.threads.name |
123125
| Endpoint.metrics.uptime.endpoint |

custom_documentation/src/endpoint/data_stream/file/windows/windows_file_rename.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,10 @@ identification:
1515
fields:
1616
endpoint:
1717
- '@timestamp'
18+
- Effective_process.entity_id
19+
- Effective_process.executable
20+
- Effective_process.name
21+
- Effective_process.pid
1822
- agent.id
1923
- agent.type
2024
- agent.version

custom_documentation/src/endpoint/data_stream/metrics/metrics.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,6 +125,8 @@ fields:
125125
- Endpoint.metrics.system_impact.registry_events.week_ms
126126
- Endpoint.metrics.system_impact.threat_intelligence_events.week_idle_ms
127127
- Endpoint.metrics.system_impact.threat_intelligence_events.week_ms
128+
- Endpoint.metrics.system_impact.win32k_events.week_idle_ms
129+
- Endpoint.metrics.system_impact.win32k_events.week_ms
128130
- Endpoint.metrics.threads.cpu.mean
129131
- Endpoint.metrics.threads.name
130132
- Endpoint.metrics.uptime.endpoint

0 commit comments

Comments
 (0)