-
Notifications
You must be signed in to change notification settings - Fork 429
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Cisco ISE] Improve ECS mappings #10538
Comments
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
I checked the latest pipeline tests
the Line 204 in d770649
adding
adding
Line 207 in d770649
Adding:
Will have PR shortly. |
It would be helpful if you have some example logs for |
Some of the fields in our Cisco ISE integration are not-complaint with ECS and can be improved upon. Below are the fields which require improvements, based on customer request:
event.category: authentication
andevent.outcome: success
needs to be set for events wherecisco_ise.log.category.name: CISE_Passed_Authentications
(currently this is missing)event.category: authentication
andevent.outcome: failure
is missing for events whereevent.code is [5404, 5434,5413]
event.kind: event
is not being being set for any eventsRename
cisco_ise.log.endpoint.mac.address
toclient.mac
Can request sample data if required.
The text was updated successfully, but these errors were encountered: