Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Winlogbeats Windows object name GUID translation #21274

Closed
synikitin opened this issue Sep 23, 2020 · 8 comments
Closed

Winlogbeats Windows object name GUID translation #21274

synikitin opened this issue Sep 23, 2020 · 8 comments
Assignees
Labels
Team:Security-Windows Platform Windows Platform Team in Security Solution

Comments

@synikitin
Copy link

synikitin commented Sep 23, 2020

Hi,

I know translation of SIDs got added. Is there any plan to add GUID translations? Tying this back to https://discuss.elastic.co/t/winlogbeat-displaying-guid-in-windows-events-instead-of-object-name/71442.

It seems possible given Splunk's universal forwarded has an option for this https://community.splunk.com/t5/Getting-Data-In/Translate-GUID-in-Windows-Event-Log/m-p/104021.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Sep 23, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Sep 24, 2020
@bondbig
Copy link

bondbig commented Apr 22, 2021

Any news on this one? This is quite embarrassing, really

@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@botelastic
Copy link

botelastic bot commented Apr 26, 2022

Hi!
We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1.
Thank you for your contribution!

@botelastic botelastic bot added the Stalled label Apr 26, 2022
@botelastic botelastic bot closed this as completed Oct 23, 2022
@willemdh
Copy link

This would be very useful imho. Sorry to see its closed

@narph narph reopened this Jan 12, 2023
@botelastic botelastic bot removed the Stalled label Jan 12, 2023
@botelastic
Copy link

botelastic bot commented Jan 12, 2024

Hi!
We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1.
Thank you for your contribution!

@elasticmachine
Copy link
Collaborator

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

@botelastic botelastic bot removed the Stalled label Jan 31, 2024
@marc-gr marc-gr self-assigned this Sep 19, 2024
@marc-gr
Copy link
Contributor

marc-gr commented Dec 31, 2024

A new processor has been added to allow translation of ldap attributes (GUIDs included) https://www.elastic.co/guide/en/beats/filebeat/8.17/processor-translate-guid.html

@marc-gr marc-gr closed this as completed Dec 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:Security-Windows Platform Windows Platform Team in Security Solution
Projects
None yet
Development

No branches or pull requests

8 participants