Skip to content

[azure,o365,m365_defender] ECS mapping improvements #13989

@chrisberkhout

Description

@chrisberkhout

Description

Various suggested ECS field mapping updates to improve correlation of ingested events with other security telemetry, for the integrations azure, o365 and m365_defender.

Similar to the earlier work for symantec_endpoint_security in #13476.

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions