Skip to content

Commit eb6f476

Browse files
committed
Add entropy and header_bytes for Linux file events
1 parent 7689c98 commit eb6f476

File tree

6 files changed

+10
-0
lines changed

6 files changed

+10
-0
lines changed

custom_documentation/doc/endpoint/file/linux/linux_file_create.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,8 @@ This event is generated when a file is created.
2828
| event.outcome |
2929
| event.sequence |
3030
| event.type |
31+
| file.Ext.entropy |
32+
| file.Ext.header_bytes |
3133
| file.extension |
3234
| file.hash.sha256 |
3335
| file.name |

custom_documentation/doc/endpoint/file/linux/linux_file_delete.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,7 @@ This event is generated when a file is deleted.
2828
| event.outcome |
2929
| event.sequence |
3030
| event.type |
31+
| file.Ext.entropy |
3132
| file.extension |
3233
| file.name |
3334
| file.path |

custom_documentation/doc/endpoint/file/linux/linux_file_rename.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,8 @@ This event is generated when a file is renamed.
2828
| event.outcome |
2929
| event.sequence |
3030
| event.type |
31+
| file.Ext.entropy |
32+
| file.Ext.header_bytes |
3133
| file.Ext.original.extension |
3234
| file.Ext.original.name |
3335
| file.Ext.original.path |

custom_documentation/src/endpoint/data_stream/file/linux/linux_file_create.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
- event.outcome
3434
- event.sequence
3535
- event.type
36+
- file.Ext.entropy
37+
- file.Ext.header_bytes
3638
- file.extension
3739
- file.hash.sha256
3840
- file.name

custom_documentation/src/endpoint/data_stream/file/linux/linux_file_delete.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ fields:
3333
- event.outcome
3434
- event.sequence
3535
- event.type
36+
- file.Ext.entropy
3637
- file.extension
3738
- file.name
3839
- file.path

custom_documentation/src/endpoint/data_stream/file/linux/linux_file_rename.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ fields:
3333
- event.outcome
3434
- event.sequence
3535
- event.type
36+
- file.Ext.entropy
37+
- file.Ext.header_bytes
3638
- file.Ext.original.extension
3739
- file.Ext.original.name
3840
- file.Ext.original.path

0 commit comments

Comments
 (0)