forked from elastic/ecs
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Remove
expected_values
from *.indicator.name field defs (elastic#2281)
* remove expected_values for indicator.name fields * generate artifacts * changelog
- Loading branch information
Showing
9 changed files
with
58 additions
and
158 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -10526,19 +10526,7 @@ example: `2020-11-05T17:25:47.000Z` | |
|
||
a| The display name indicator in an UI friendly format | ||
|
||
Expected values for this field: | ||
|
||
* `5.2.75.227` | ||
* `2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6` | ||
* `https://example.com/some/path` | ||
* `example.com` | ||
* `373d34874d7bc89fd4cefa6272ee80bf` | ||
* `b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7` | ||
* `[email protected]` | ||
* `HKLM\\SOFTWARE\\Microsoft\\Active` | ||
* `13335` | ||
* `00:00:5e:00:53:af` | ||
* `8008` | ||
URL, IP address, email address, registry key, port number, hash value, or other relevant name can serve as the display name. | ||
|
||
type: keyword | ||
|
||
|
@@ -11084,19 +11072,7 @@ example: `2020-11-05T17:25:47.000Z` | |
|
||
a| The display name indicator in an UI friendly format | ||
|
||
Expected values for this field: | ||
|
||
* `5.2.75.227` | ||
* `2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6` | ||
* `https://example.com/some/path` | ||
* `example.com` | ||
* `373d34874d7bc89fd4cefa6272ee80bf` | ||
* `b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7` | ||
* `[email protected]` | ||
* `HKLM\\SOFTWARE\\Microsoft\\Active` | ||
* `13335` | ||
* `00:00:5e:00:53:af` | ||
* `8008` | ||
URL, IP address, email address, registry key, port number, hash value, or other relevant name can serve as the display name. | ||
|
||
type: keyword | ||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -16325,20 +16325,11 @@ threat.enrichments.indicator.modified_at: | |
type: date | ||
threat.enrichments.indicator.name: | ||
dashed_name: threat-enrichments-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or other | ||
relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.enrichments.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
@@ -19044,20 +19035,11 @@ threat.indicator.modified_at: | |
type: date | ||
threat.indicator.name: | ||
dashed_name: threat-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or other | ||
relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -18992,20 +18992,11 @@ threat: | |
type: date | ||
threat.enrichments.indicator.name: | ||
dashed_name: threat-enrichments-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or | ||
other relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.enrichments.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
@@ -21717,20 +21708,11 @@ threat: | |
type: date | ||
threat.indicator.name: | ||
dashed_name: threat-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or | ||
other relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -16256,20 +16256,11 @@ threat.enrichments.indicator.modified_at: | |
type: date | ||
threat.enrichments.indicator.name: | ||
dashed_name: threat-enrichments-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or other | ||
relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.enrichments.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
@@ -18975,20 +18966,11 @@ threat.indicator.modified_at: | |
type: date | ||
threat.indicator.name: | ||
dashed_name: threat-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or other | ||
relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -18912,20 +18912,11 @@ threat: | |
type: date | ||
threat.enrichments.indicator.name: | ||
dashed_name: threat-enrichments-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or | ||
other relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.enrichments.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
@@ -21637,20 +21628,11 @@ threat: | |
type: date | ||
threat.indicator.name: | ||
dashed_name: threat-indicator-name | ||
description: The display name indicator in an UI friendly format | ||
description: 'The display name indicator in an UI friendly format | ||
|
||
URL, IP address, email address, registry key, port number, hash value, or | ||
other relevant name can serve as the display name.' | ||
example: 5.2.75.227 | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
flat_name: threat.indicator.name | ||
ignore_above: 1024 | ||
level: extended | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -111,18 +111,9 @@ | |
short: Indicator display name | ||
description: > | ||
The display name indicator in an UI friendly format | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
|
||
URL, IP address, email address, registry key, port number, hash value, | ||
or other relevant name can serve as the display name. | ||
example: 5.2.75.227 | ||
|
||
- name: enrichments.indicator.description | ||
|
@@ -419,18 +410,9 @@ | |
short: Indicator display name | ||
description: > | ||
The display name indicator in an UI friendly format | ||
expected_values: | ||
- 5.2.75.227 | ||
- 2a02:cf40:add:4002:91f2:a9b2:e09a:6fc6 | ||
- https://example.com/some/path | ||
- example.com | ||
- 373d34874d7bc89fd4cefa6272ee80bf | ||
- b0e914d1bbe19433cc9df64ea1ca07fe77f7b150b511b786e46e007941a62bd7 | ||
- [email protected] | ||
- HKLM\\SOFTWARE\\Microsoft\\Active | ||
- 13335 | ||
- 00:00:5e:00:53:af | ||
- 8008 | ||
|
||
URL, IP address, email address, registry key, port number, hash value, | ||
or other relevant name can serve as the display name. | ||
example: 5.2.75.227 | ||
|
||
- name: indicator.description | ||
|