Skip to content

[meta] ECS 8.5 Updates (Security External Integrations) #4337

Description

@efd6

This is a meta issue to track ECS 8.5 updates to Fleet integrations maintained by the elastic/security-external-integrations team.

ECS 8.5 Changes

This is a summary of the changes in ECS 8.5. You can view the official changelog here.

Added

No features added to ECS in 8.5 required changes in SEI packages.

  • Adding risk.* fields as experimental.
  • Adding process.io.* as beta fields.
  • Adding process.tty.rows and process.tty.columns as beta fields.
  • Changed process.env_vars field type to be an array of keywords.
  • process.attested_user and process.attested_groups as beta fields.
  • Added risk.* fieldset to beta.

SEI owned Integrations

All SEI integrations are updated in #4285 (currently updating to v8.5.0-rc1).

Prior to this PR a number of preparatory PRs were required to bring packages up to date:

Integrations SEI contributes to

I reviewed these to see if they were affected any changes to ECS; as above no changes in the ECS have any impact in these packages and they will not be touched.

  • aws.cloudtrail
  • aws.vpcflow
  • system.application
  • system.auth
  • system.security
  • system.system
  • windows.forwarded
  • windows.powershell
  • windows.powershell_operational
  • windows.sysmon_operational

Metadata

Metadata

Assignees

Labels

8.5 candidateenhancementNew feature or requestintegrationLabel used for meta issues tracking each integration

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions