-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] Adding aggregations for endpoint events #72705
[Security Solution] Adding aggregations for endpoint events #72705
Conversation
bool: { | ||
should: [ | ||
{ | ||
term: { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We're treating library
and driver
events as image load.
bool: { | ||
filter: [ | ||
{ | ||
bool: { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Network is anything but dns
should: [ | ||
{ | ||
bool: { | ||
filter: [ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Security events for endpoint should be an array of two values for event.category == [session, authentication]
💚 Build SucceededBuild metrics
To update your PR or re-run it, just comment with: |
Can you make an issue for cleaning up the names that we can come back to later on? |
Pinging @elastic/endpoint-app-team (Feature:Endpoint) |
Pinging @elastic/endpoint-data-visibility-team (Team:Endpoint Data Visibility) |
Summary
This PR adds support for aggregating totals for endpoint data and endgame data. We should probably do some cleanup on the variable names to switch them over to
endpoint
or some combination ofendpoint
andendgame
. This is a bug fix so I have not done the refactoring in this PR.Endpoint only data
data:image/s3,"s3://crabby-images/e1a7a/e1a7ad3c8b0251574d6d46fe38ade19959d7fb62" alt="image"
Endgame Data
data:image/s3,"s3://crabby-images/72588/725884abcc00fff813f1c97bf78b1fbd34b8ac63" alt="image"
Both Endpoint and Endgame Data
data:image/s3,"s3://crabby-images/af228/af228351e50138800050c7550c459f573009b012" alt="image"