NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1132 most downloaded on NuGet
Maps Elastic Common Schema (ECS) to .NET types including (de)serialization using System.Text.Json
Last release 1 years ago
13 Aug 2025
Release timing varies
gaps range from 2 weeks to 8 months
Some releases are documented
notes for 11 of 21 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
27 releases · first in 2019
View the full list of issues and PRs
View the full list of issues and PRs
One column per quarter.
View the full list of issues and PRs
View the full list of issues and PRs
View the full list of issues and PRs
View the full list of issues and PRs
View the full list of issues and PRs
View the full list of issues and PRs
8.12.1: Remove WriteEvent usages (#453)
Compare
View the full list of issues and PRs
View the full list of issues and PRs
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Clarified examples and definitions regarding vulnerabilities. #758
b5bbe25
This commit was created on GitHub.com and signed with GitHub’s verified signature . The key has expired.
GPG key ID: 4AEE18F83AFDEB23 Expired
Verified Learn about vigilant mode .
In this release, we continue fleshing out categorization by introducing the "network" and "iam" categories, with related event types.
We're adding new field sets: "dll", "pe", "code_signature", "interface" & "vlan". We're also adding a few fields here and there (check out the details below).
Implementers consuming ECS artifacts like generated/ecs/*.yml programmatically will be happy to know that we now clearly identify which fields are expected to contain an array of values. Shout-out to contributors on the ecs-logging libraries for raising this 👋🏼.
Finally, starting with ECS 1.5.0, the project is using Python 3.7.
Added dll.* fields #679
Added related.hash to keep track of all hashes seen on an event. #711
Added fieldset for PE metadata. #731
Added code_signature fieldset. #733
Added missing hash fields at process.parent.hash.* . #739
Added globally unique identifier entity_id to process and process.parent . #747
Added interface, vlan, observer zone fields #752
Added rule.author , rule.license fields #754
Added iam value for event.category and three related values for event.type . #756
Added fields event.reference and event.url to hold link to additional event info/actions. #757
Added file.mime_type to include MIME type information on file structures #760
Added event.category value of network and associated event.type values. #761
Temporary workaround for Beats templates' default_field growing too big. #687
Identify which fields should contain arrays of values, rather than scalar values. #727 , #661
Clarified examples and definitions regarding vulnerabilities. #758
Updated definition of event.outcome based on community feedback. #759
ECS scripts now use Python 3.6+. #674
schema_reader.py now reliably supports chaining reusable fieldsets together. #722
Allow the artifact generator to consider and output only a subset of fields. #737
Add support for reusing fields in places other than the top level of the destination fieldset. #739
Add support for specifying the directory to write the generated files. #748
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →