Git Product home page Git Product logo

Comments (11)

r00tu53r avatar r00tu53r commented on July 17, 2024 1

@r00tu53r is this something you could look into as you're upgrading to ECS 8.0/8.1?

Sure @jamiehynds I'll take a look.

from integrations.

chrisberkhout avatar chrisberkhout commented on July 17, 2024 1

These issues do seem to remain in the beats module that was linked to, but not in the o365 integration (in this repo).

For the integration:

  1. event.category is an array
  2. The information from the OriginatingServer field is split up into address, domain and IP. UserID values such as NT AUTHORITY\\SYSTEM (Microsoft.Exchange.ServiceHost) are simply copied to user.id and appear without further parsing, but that seems like a good choice. Values in the user@domain format do have further parsing.
  3. As mentioned in point 2, server address, domain and IP are set correctly.

from integrations.

elasticmachine avatar elasticmachine commented on July 17, 2024

Pinging @elastic/siem (Team:SIEM)

from integrations.

elasticmachine avatar elasticmachine commented on July 17, 2024

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

from integrations.

botelastic avatar botelastic commented on July 17, 2024

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

from integrations.

willemdh avatar willemdh commented on July 17, 2024

Ping

from integrations.

jamiehynds avatar jamiehynds commented on July 17, 2024

@r00tu53r is this something you could look into as you're upgrading to ECS 8.0/8.1?

from integrations.

botelastic avatar botelastic commented on July 17, 2024

Hi!
We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1.
Thank you for your contribution!

from integrations.

jamiehynds avatar jamiehynds commented on July 17, 2024

Keeping open and moving to the integrations repo.

from integrations.

jamiehynds avatar jamiehynds commented on July 17, 2024

@chrisberkhout can you confirm if this feedback has been addressed in your latest ECS updates to O365? Thanks!

from integrations.

jamiehynds avatar jamiehynds commented on July 17, 2024

Closing as we've recently reviewed and updated our O365 ECS mappings.

from integrations.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.