Event.type field in system module logs not ECS compliant

Good morning,

I activated the system module of Filebeat (version 8.7.1) in order to collect the ssh logins on an Ubuntu VM. I can see them on Kibana, but the event.type field is info event if it is an authentication log category.

The event.type should be start as described in the ECS documentation, shouldn’t it?

{
  "_index": ".ds-filebeat-8.7.1-2023.05.15-000001",
  "_source": {
       "log": {
           "file": {
               "path": "/var/log/auth.log"
           }
      },
      "event": {
           "kind": "event",
           "module": "system",
           "action": "ssh_login",
           "type": [
                "info"
            ],
           "category": [
                "authentication",
                "session"
            ],
            "dataset": "system.auth",
            "outcome": "success"
    },
}

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.