Expand timestamp override tests (#1907)

* Expand timestamp_override tests
* removed timestamp_override from eql sequence rules
* add config entry for eql rules with beats index and t_o
* add timestamp_override to missing fields
This commit is contained in:
Justin Ibarra
2022-04-01 15:27:08 -08:00
committed by GitHub
parent 648daf1237
commit 6bdfddac8e
233 changed files with 1695 additions and 731 deletions
+2 -1
View File
@@ -1,7 +1,7 @@
[metadata]
creation_date = "2022/03/15"
maturity = "production"
updated_date = "2022/03/24"
updated_date = "2022/03/31"
[rule]
author = ["Elastic"]
@@ -48,3 +48,4 @@ reference = "https://attack.mitre.org/techniques/T1059/004/"
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"