Integration Name
Elastic Security [elastic_security]
Dataset Name
endpoint.events.file, endpoint.events.device, endpoint.events.network, endpoint.events.process
Integration Version
9.2.0
Agent Version
9.2.1
Agent Output Type
elasticsearch
Elasticsearch Version
9.2.3
OS Version and Architecture
All (Windows, Ubuntu, RHEL, macOS)
Software/API Version
No response
Error Message
No response
Event Original
No response
What did you do?
Collected logs from various OSes using Defend and other integrations (system, auditd manager, etc).
What did you see?
Logs collected from Defend report different OS values for the following fields:
- host.os.family
- host.os.name
- host.os.platform
- host.os.version
For macOS, the fields are all null.
What did you expect to see?
I expect to see the same host OS values across all integrations.
Anything else?
No response
Integration Name
Elastic Security [elastic_security]
Dataset Name
endpoint.events.file, endpoint.events.device, endpoint.events.network, endpoint.events.process
Integration Version
9.2.0
Agent Version
9.2.1
Agent Output Type
elasticsearch
Elasticsearch Version
9.2.3
OS Version and Architecture
All (Windows, Ubuntu, RHEL, macOS)
Software/API Version
No response
Error Message
No response
Event Original
No response
What did you do?
Collected logs from various OSes using Defend and other integrations (system, auditd manager, etc).
What did you see?
Logs collected from Defend report different OS values for the following fields:
For macOS, the fields are all null.
What did you expect to see?
I expect to see the same host OS values across all integrations.
Anything else?
No response