Skip to content

[DOCS] Document Rule Creation and Alert Triage workflows for leveraging non-ECS/custom/runtime fields  #1421

@spong

Description

@spong

Description

Historically, if users wanted to leverage custom fields with the Rule & Alerts workflows they could just add a custom mapping template to the .siem-signals index and they would be good to go. With changes implemented as part of RAC/Rule Registry, custom mapping templates are no longer supported and users are instead encouraged to leverage runtime fields to achieve searching/filtering capabilities on non-ECS/custom fields. That said, some variants of runtime fields aren't fully supported between rules and alerts (see elastic/kibana#103587), so there are some dev dependencies to fulfill before we can document a complete workflow.

Runtime field support:

Tangential dev issues:

Metadata

Metadata

Assignees

No one assigned

    Labels

    Effort: LargeIssues that require significant planning, research, writing, and testingPriority: LowIssues that need attention, but are not urgentTeam: Detections/ResponseDetections and ResponseTeam: Docsv8.2.0

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions