-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Filebeat module Checkpoint - add ECS authentication fields for SIEM #32230
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
@leweafan Can you check the syntax of the first event in the examples you have provided? The mac address is quoted with escaped double quotes. Is this intentional?
|
@efd6 thanks for help with this issue! Your are right escape character is unnecessary. My bad. Fixed the message. |
@leweafan What model / version of Checkpoint were these log samples taken from? It's useful to know the lineage of the log samples we have. |
@andrewkroh we have R80.30 and R80.40 versions. |
Describe the enhancement:
Checkpoint log has authentication messages for successful and failed attempt. But ECS fields important for SIEM like
event.category, event.type, event.action, event.outcome are missing.
Authentication success/failure messages have event.action:
Successful authentication message should have fields:
Failed authentication message should have fields:
Describe a specific use case for the enhancement or feature:
Steps to reproduce
Result
The text was updated successfully, but these errors were encountered: