Winlogbeat Original Field remove

Why some field are remove when convert to ECS ?
For exemple DestinationIsIpv6 from sysmon:

  • 'winlog.event_data.SourceIsIpv6' is remove after create 'network.type'.

As I have to work with beat agent and industrial system (no beat allowed) I have to write 2 query to find the same information :frowning_face:.


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.