ECS Release Candidate
Schema Changes
Added
- Adding
risk.*
fields as experimental. #1994, #2010 - Adding
process.io.*
as beta fields. #1956, #2031 - Adding
process.tty.rows
andprocess.tty.columns
as beta fields. #2031 - Changed
process.env_vars
field type to be an array of keywords. #2038 process.attested_user
andprocess.attested_groups
as beta fields. #2050- Added
risk.*
fieldset to beta. #2051
Improvements
- Advances
threat.enrichments.indicator
to GA. #1928 - Added
ios
andandroid
as valid values foros.type
#1999