The action being observed in an event should be captured in event.action. There's also an opportunity to leverage the categorization fields to better capture the "what it is" of the event.
For example, using the current example web filter event:
I would say no since the connection is being denied and the resource ultimately wasn't accessed.
Is event.outcome "success" correct for a connection being denied?
From the perspective of the entity that emitted the event, the web filter, the blocked connection was a successful and expected operation, so success is appropriate.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.