Skip to content

symantec_endpoint using invalid field values according to ECS #3050

@jsoriano

Description

@jsoriano
[0] parsing field value failed: field "event.type"'s value "process" is not one of the allowed values (access, admin, allowed, change, connection, creation, deletion, denied, end, error, group, indicator, info, installation, protocol, start, user)

"process" => use "event.category: process" instead?

Part of #3016

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions