Skip to content

Commit d411744

Browse files
committed
Add generated files
1 parent 817cb08 commit d411744

File tree

13 files changed

+111
-0
lines changed

13 files changed

+111
-0
lines changed

docs/fields/field-details.asciidoc

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9060,6 +9060,25 @@ A concrete example is IP addresses, which can be under host, observer, source, d
90609060

90619061
// ===============================================================
90629062

9063+
|
9064+
[[field-related-entity]]
9065+
<<field-related-entity, related.entity>>
9066+
9067+
a| All the entity identifiers related to the document. If the document contains multiple entities, identifiers belonging to different entities will be present. Example identifiers include Cloud Resource Ids, ARNs, email addresses, or hostnames.
9068+
9069+
type: keyword
9070+
9071+
9072+
Note: this field should contain an array of values.
9073+
9074+
9075+
9076+
9077+
9078+
| extended
9079+
9080+
// ===============================================================
9081+
90639082
|
90649083
[[field-related-hash]]
90659084
<<field-related-hash, related.hash>>

experimental/generated/beats/fields.ecs.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7864,6 +7864,15 @@
78647864
type: group
78657865
default_field: true
78667866
fields:
7867+
- name: entity
7868+
level: extended
7869+
type: keyword
7870+
ignore_above: 1024
7871+
description: All the entity identifiers related to the document. If the document
7872+
contains multiple entities, identifiers belonging to different entities will
7873+
be present. Example identifiers include Cloud Resource Ids, ARNs, email addresses,
7874+
or hostnames.
7875+
default_field: false
78677876
- name: hash
78687877
level: extended
78697878
type: keyword

experimental/generated/csv/fields.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1016,6 +1016,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Normalization,Example,Description
10161016
8.12.0-dev+exp,true,registry,registry.key,keyword,core,,SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe,Hive-relative path of keys.
10171017
8.12.0-dev+exp,true,registry,registry.path,keyword,core,,HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\Debugger,"Full path, including hive, key and value"
10181018
8.12.0-dev+exp,true,registry,registry.value,keyword,core,,Debugger,Name of the value written.
1019+
8.12.0-dev+exp,true,related,related.entity,keyword,extended,array,,All the entity identifiers
10191020
8.12.0-dev+exp,true,related,related.hash,keyword,extended,array,,All the hashes seen on your event.
10201021
8.12.0-dev+exp,true,related,related.hosts,keyword,extended,array,,All the host identifiers seen on your event.
10211022
8.12.0-dev+exp,true,related,related.ip,ip,extended,array,,All of the IPs seen on your event.

experimental/generated/ecs/ecs_flat.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12796,6 +12796,20 @@ registry.value:
1279612796
normalize: []
1279712797
short: Name of the value written.
1279812798
type: keyword
12799+
related.entity:
12800+
dashed_name: related-entity
12801+
description: All the entity identifiers related to the document. If the document
12802+
contains multiple entities, identifiers belonging to different entities will be
12803+
present. Example identifiers include Cloud Resource Ids, ARNs, email addresses,
12804+
or hostnames.
12805+
flat_name: related.entity
12806+
ignore_above: 1024
12807+
level: extended
12808+
name: entity
12809+
normalize:
12810+
- array
12811+
short: All the entity identifiers
12812+
type: keyword
1279912813
related.hash:
1280012814
dashed_name: related-hash
1280112815
description: All the hashes seen on your event. Populating this field, then using

experimental/generated/ecs/ecs_nested.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15226,6 +15226,20 @@ related:
1522615226
`related.ip`, you can then search for a given IP trivially, no matter where it
1522715227
appeared, by querying `related.ip:192.0.2.15`.'
1522815228
fields:
15229+
related.entity:
15230+
dashed_name: related-entity
15231+
description: All the entity identifiers related to the document. If the document
15232+
contains multiple entities, identifiers belonging to different entities will
15233+
be present. Example identifiers include Cloud Resource Ids, ARNs, email addresses,
15234+
or hostnames.
15235+
flat_name: related.entity
15236+
ignore_above: 1024
15237+
level: extended
15238+
name: entity
15239+
normalize:
15240+
- array
15241+
short: All the entity identifiers
15242+
type: keyword
1522915243
related.hash:
1523015244
dashed_name: related-hash
1523115245
description: All the hashes seen on your event. Populating this field, then

experimental/generated/elasticsearch/composable/component/related.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,10 @@
88
"properties": {
99
"related": {
1010
"properties": {
11+
"entity": {
12+
"ignore_above": 1024,
13+
"type": "keyword"
14+
},
1115
"hash": {
1216
"ignore_above": 1024,
1317
"type": "keyword"

experimental/generated/elasticsearch/legacy/template.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4644,6 +4644,10 @@
46444644
},
46454645
"related": {
46464646
"properties": {
4647+
"entity": {
4648+
"ignore_above": 1024,
4649+
"type": "keyword"
4650+
},
46474651
"hash": {
46484652
"ignore_above": 1024,
46494653
"type": "keyword"

generated/beats/fields.ecs.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7814,6 +7814,15 @@
78147814
type: group
78157815
default_field: true
78167816
fields:
7817+
- name: entity
7818+
level: extended
7819+
type: keyword
7820+
ignore_above: 1024
7821+
description: All the entity identifiers related to the document. If the document
7822+
contains multiple entities, identifiers belonging to different entities will
7823+
be present. Example identifiers include Cloud Resource Ids, ARNs, email addresses,
7824+
or hostnames.
7825+
default_field: false
78177826
- name: hash
78187827
level: extended
78197828
type: keyword

generated/csv/fields.csv

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1009,6 +1009,7 @@ ECS_Version,Indexed,Field_Set,Field,Type,Level,Normalization,Example,Description
10091009
8.12.0-dev,true,registry,registry.key,keyword,core,,SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe,Hive-relative path of keys.
10101010
8.12.0-dev,true,registry,registry.path,keyword,core,,HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\Debugger,"Full path, including hive, key and value"
10111011
8.12.0-dev,true,registry,registry.value,keyword,core,,Debugger,Name of the value written.
1012+
8.12.0-dev,true,related,related.entity,keyword,extended,array,,All the entity identifiers
10121013
8.12.0-dev,true,related,related.hash,keyword,extended,array,,All the hashes seen on your event.
10131014
8.12.0-dev,true,related,related.hosts,keyword,extended,array,,All the host identifiers seen on your event.
10141015
8.12.0-dev,true,related,related.ip,ip,extended,array,,All of the IPs seen on your event.

generated/ecs/ecs_flat.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12727,6 +12727,20 @@ registry.value:
1272712727
normalize: []
1272812728
short: Name of the value written.
1272912729
type: keyword
12730+
related.entity:
12731+
dashed_name: related-entity
12732+
description: All the entity identifiers related to the document. If the document
12733+
contains multiple entities, identifiers belonging to different entities will be
12734+
present. Example identifiers include Cloud Resource Ids, ARNs, email addresses,
12735+
or hostnames.
12736+
flat_name: related.entity
12737+
ignore_above: 1024
12738+
level: extended
12739+
name: entity
12740+
normalize:
12741+
- array
12742+
short: All the entity identifiers
12743+
type: keyword
1273012744
related.hash:
1273112745
dashed_name: related-hash
1273212746
description: All the hashes seen on your event. Populating this field, then using

0 commit comments

Comments
 (0)