elastic / elastic/endpoint-package

[Integration Name]: Elastic Defend reports OS information differently than non-Defend integrations

Open
#772 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
33
Forks
20
Avg merge
2d 16h
Merged PRs (30d)
5

Description

### Integration Name

Elastic Security [elastic_security]

### Dataset Name

endpoint.events.file, endpoint.events.device, endpoint.events.network, endpoint.events.process

### Integration Version

9.2.0

### Agent Version

9.2.1

### Agent Output Type

elasticsearch

### Elasticsearch Version

9.2.3

### OS Version and Architecture

All (Windows, Ubuntu, RHEL, macOS)

### Software/API Version

_No response_

### Error Message

_No response_

### Event Original

_No response_

### What did you do?

Collected logs from various OSes using Defend and other integrations (system, auditd manager, etc).

### What did you see?

Logs collected from Defend report different OS values for the following fields:
- host.os.family
- host.os.name
- host.os.platform
- host.os.version

For macOS, the fields are all null.

Image
Image
Image
Image

### What did you expect to see?

I expect to see the same host OS values across all integrations.

### Anything else?

_No response_

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.