Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add All Original Messages To event.original ECS Field #34465

Closed
UcanInfosec opened this issue Feb 2, 2023 · 2 comments
Closed

Add All Original Messages To event.original ECS Field #34465

UcanInfosec opened this issue Feb 2, 2023 · 2 comments
Labels
needs_team Indicates that the issue/PR needs a Team:* label Stalled

Comments

@UcanInfosec
Copy link

Describe the enhancement:
Add code in modules to Add All Original Messages To event.original ECS Field

Describe a specific use case for the enhancement or feature:
This would allow for future use of the original message. And some events have the message field. Would also allow future parsing or work as original message is preserved.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Feb 2, 2023
@botelastic
Copy link

botelastic bot commented Feb 2, 2023

This issue doesn't have a Team:<team> label.

@botelastic
Copy link

botelastic bot commented Feb 2, 2024

Hi!
We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1.
Thank you for your contribution!

@botelastic botelastic bot added the Stalled label Feb 2, 2024
@botelastic botelastic bot closed this as completed Jul 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs_team Indicates that the issue/PR needs a Team:* label Stalled
Projects
None yet
Development

No branches or pull requests

1 participant