Skip to content

Add event.category to Asset Discovery #3890

@JordanSh

Description

@JordanSh

The event.category field is missing from Asset Discovery logs, which is essential for better event classification. This field is used by SIEM Readiness for categorizing logs.

The following allowed values should be used for the event.category field:

  • api
  • authentication
  • configuration
  • database
  • driver
  • email
  • file
  • host
  • iam
  • intrusion_detection
  • library
  • malware
  • network
  • package
  • process
  • registry
  • session
  • threat
  • vulnerability
  • web

optional: event.type and perhaps other essential fields should be considered as well

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions