Skip to content

Windows/System security: process.args_count (4688), 5136 event.reason & ObjectDN#17921

Open
marc-gr wants to merge 6 commits intoelastic:mainfrom
marc-gr:windows-system-security-4688-5136
Open

Windows/System security: process.args_count (4688), 5136 event.reason & ObjectDN#17921
marc-gr wants to merge 6 commits intoelastic:mainfrom
marc-gr:windows-system-security-4688-5136

Conversation

@marc-gr
Copy link
Contributor

@marc-gr marc-gr commented Mar 20, 2026

Summary

Enhancements for Windows Security events in windows forwarded and system security data streams (pipelines kept in sync).

Changes

Versions

  • windows 3.6.1 → 3.7.0
  • system 2.13.0 → 2.14.0

Testing

elastic-package test pipeline -v -C packages/windows -d forwarded
elastic-package test pipeline -v -C packages/system -d security

Closes #14767
Closes #15308
Closes #16965

…ectDN

- Add process.args_count for event 4688 (elastic#14767)
- Map OperationType to event.reason for event 5136 (elastic#15308)
- Parse ObjectDN for 5136 into user.target/group/host by ObjectClass (elastic#16965)

Keep windows.forwarded and system.security pipelines in sync.
@marc-gr marc-gr requested review from a team as code owners March 20, 2026 08:43
@marc-gr marc-gr added Integration:windows Windows Integration:system System Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] labels Mar 20, 2026
@elasticmachine
Copy link

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

@marc-gr marc-gr enabled auto-merge (squash) March 20, 2026 09:32
@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

@pierrehilbert pierrehilbert added the Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] label Mar 20, 2026
@elasticmachine
Copy link

Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:system System Integration:windows Windows Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

3 participants