-
Notifications
You must be signed in to change notification settings - Fork 42
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Host information is incorrect #2081
Comments
Linking a reference document: https://docs.google.com/spreadsheets/d/1p7m6c-sPn_Orgfc-jwJod9wupvF-2Qp7SDrDLle15_8/edit#gid=124010285 |
Pushed a draft PR with changes. Tested on Azure, IT tests passing. PTAL. |
I have prepared separate PRs for Please look at PR descriptions and code to find out which rules got the new Elastic Common Schema fields, since it affects only some of them. The
|
Motivation
Alerts generated from rules that were created from findings display wrong host information on the alert host flyout - the information displayed belongs to the host where the agent is running which is unrelated to the actual alert or misconfiguration (related only in KSPM). The second problem is that for alerts and misconfigurations that actually have a host or user relevant to them (which are not many) we didn't map the host or user Information to the relevant ECS fields.
Definition of done
What needs to be completed at the end of this task
host.name
anduser.name
with the correct valuesReleated
cc @JordanSh @eyalkraft
The text was updated successfully, but these errors were encountered: