Hii Everyone,
I am trying to map the fields used in my index to the ECS fields so that it gets populated in the SIEM APP. I have mapped fields like username , hostname and event action with the ECS fields and its getting populated in the SIEM App.
Basically I want all the fields used in the SIEM APP , So that I can map and populate my fields in SIEM APP.