-
Notifications
You must be signed in to change notification settings - Fork 522
Closed
Labels
Integration:trendmicroTrend Micro Deep SecurityTrend Micro Deep SecurityTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]bugSomething isn't working, use only for issuesSomething isn't working, use only for issuesmapping/pipeline issue
Description
For the trendmicro integration, the default pipeline sets event.category: network and event.type: [connection,access,allowed,denied,info]. Having these categorization fields mass applied to all events makes it more difficult for users to gain insight into the events.
ECS event.category allowed values: https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-category.html
ECS event.type allowed values: https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-type.html
Metadata
Metadata
Assignees
Labels
Integration:trendmicroTrend Micro Deep SecurityTrend Micro Deep SecurityTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]bugSomething isn't working, use only for issuesSomething isn't working, use only for issuesmapping/pipeline issue