Skip to content

Add missing custom documentation fields to logoff security events #645

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Jun 23, 2025

Conversation

AsuNa-jp
Copy link
Contributor

@AsuNa-jp AsuNa-jp commented Jun 23, 2025

Change Summary

This PR adds the following fields to logoff security events custom documentation.

  • process.Ext.protection
  • process.Ext.token.integrity_level_name
  • process.command_line
  • process.name
  • process.parent.executable
  • process.pid

Reference: https://github.com/elastic/endpoint-dev/pull/16550

Release Target

8.19/9.1

Q/A

For mapping changes:

  • I ran make after making the schema changes, and committed all changes

@AsuNa-jp AsuNa-jp self-assigned this Jun 23, 2025
@AsuNa-jp AsuNa-jp marked this pull request as ready for review June 23, 2025 08:30
@AsuNa-jp AsuNa-jp requested a review from a team as a code owner June 23, 2025 08:30
@AsuNa-jp AsuNa-jp merged commit 9e5557a into main Jun 23, 2025
4 checks passed
@pzl pzl deleted the update_security_event_custom_documentation branch June 24, 2025 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants