You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please describe what you are requesting
Add an asset sub-field type with fields such as: ..._asset_ip ..._asset_mac ..._asset_owner ..._asset_location ..._asset_location
Look at existing schema fields and consider other sources of data.
Describe what change you are proposing
Adding asset information will expand our schema to further integrate with the asset functionality being built into Graylog Security. Normalizing these fields can be part of the processing sequence to help ease the adoption of asset data integration.
Describe the log source
Many.
Attach any sample logs or examples for details
For example, Winlogbeat can include host information such as:
This information should does not necessarily fit in context with fields like source_ip, destination_ip, etc. since that information is contextual to an actual network connection between a source and a host. Adding it as additional ..._asset_... sub-field(s) can provide normalized data to a potential asset pack which can supply this data to the asset functionality in Graylog Security.
The text was updated successfully, but these errors were encountered:
Please describe what you are requesting
Add an asset sub-field type with fields such as:
..._asset_ip
..._asset_mac
..._asset_owner
..._asset_location
..._asset_location
Look at existing schema fields and consider other sources of data.
Describe what change you are proposing
Adding asset information will expand our schema to further integrate with the asset functionality being built into Graylog Security. Normalizing these fields can be part of the processing sequence to help ease the adoption of asset data integration.
Describe the log source
Many.
Attach any sample logs or examples for details
For example, Winlogbeat can include host information such as:
This information should does not necessarily fit in context with fields like
source_ip
,destination_ip
, etc. since that information is contextual to an actual network connection between a source and a host. Adding it as additional..._asset_...
sub-field(s) can provide normalized data to a potential asset pack which can supply this data to the asset functionality in Graylog Security.The text was updated successfully, but these errors were encountered: