Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add domain to email.* Fields #2392

Open
wants to merge 3 commits into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.next.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ Thanks, you're awesome :-) -->
* Advanced `process.io` and `process.tty` fields to GA. #2317
* Added `threat.indicator.id`. #2324
* Added `process.group` to generated schemas. #2335
* Added `*.domain` fields to ECS `email`. #2392

#### Improvements

Expand Down
60 changes: 60 additions & 0 deletions schemas/email.yml
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,16 @@
normalize:
- array

- name: bcc.domain
level: extended
type: keyword
short: Email domain of BCC recipients.
description: >
The domain of the BCC recipients.
example: "example.com"
normalize:
- array

- name: cc.address
level: extended
type: keyword
Expand All @@ -90,6 +100,16 @@
normalize:
- array

- name: cc.domain
level: extended
type: keyword
short: Email domain of CC recipients.
description: >
The domain of the CC recipients.
example: "example.com"
normalize:
- array

- name: content_type
level: extended
type: keyword
Expand Down Expand Up @@ -126,6 +146,16 @@
normalize:
- array

- name: from.domain
level: extended
type: keyword
short: The sender's email domain.
description: >
The domain of the email sender.
example: "example.com"
normalize:
- array

- name: local_id
level: extended
type: keyword
Expand Down Expand Up @@ -164,6 +194,16 @@
normalize:
- array

- name: reply_to.domain
level: extended
type: keyword
short: Email domain of Reply To address.
description: >
The domain of the Reply To address.
example: "example.com"
normalize:
- array

- name: sender.address
level: extended
type: keyword
Expand All @@ -172,6 +212,16 @@
Per RFC 5322, specifies the address responsible for the actual transmission of
the message.

- name: sender.domain
level: extended
type: keyword
short: Email domain of sender address.
description: >
The domain of the sender address.
example: "example.com"
normalize:
- array

- name: subject
level: extended
type: keyword
Expand All @@ -193,6 +243,16 @@
normalize:
- array

- name: to.domain
level: extended
type: keyword
short: The recipient's email domain.
description: >
The domain of the email recipient.
example: "example.com"
normalize:
- array

- name: x_mailer
level: extended
type: keyword
Expand Down