This documentation contains work-in-progress information for future Elastic Stack and Cloud releases. Use the version selector to view supported release docs. It also contains some Elastic Cloud serverless information. Check out our serverless docs for more details.
Group Fields
editGroup Fields
editThe group fields are meant to represent groups that are relevant to the event.
Group Field Details
editField | Description | Level |
---|---|---|
Name of the directory the group is a member of. For example, an LDAP or Active Directory domain name. type: keyword |
extended |
|
Unique identifier for the group on the system/platform. type: keyword |
extended |
|
Name of the group. type: keyword |
extended |
Field Reuse
editThe group
fields are expected to be nested at:
-
process.attested_groups
-
process.group
-
process.real_group
-
process.saved_group
-
process.supplemental_groups
-
user.group
Note also that the group
fields may be used directly at the root of the events.