New Value for event.category: library #2153
Labels
8.7.0
bug
Something isn't working
categorization
endpoint
Relevant to elastic endpoint security
enhancement
New feature or request
Summary
Endpoint currently uses the term "library" as an event.category but it does not actually exist in the allow list. There's really no ither category that these types of events fits into and it was determined that removing this classification will break existing rules, etc.
See: https://github.com/elastic/endpoint-dev/issues/11513 - for a discussion on the matter.
Motivation:
Already used in Endpoint and not feasible to remove, so we need to add it to ECS as an allowed category.
Detailed Design:
See the endpoint-dev issue above for samples of events already generated and used in rules, etc.
The text was updated successfully, but these errors were encountered: