-
Notifications
You must be signed in to change notification settings - Fork 202
Open
Labels
Effort: LargeIssues that require significant planning, research, writing, and testingIssues that require significant planning, research, writing, and testingPriority: LowIssues that need attention, but are not urgentIssues that need attention, but are not urgentTeam: Detections/ResponseDetections and ResponseDetections and ResponseTeam: Docsv8.2.0
Description
Description
Historically, if users wanted to leverage custom fields with the Rule & Alerts workflows they could just add a custom mapping template to the .siem-signals
index and they would be good to go. With changes implemented as part of RAC/Rule Registry, custom mapping templates are no longer supported and users are instead encouraged to leverage runtime fields to achieve searching/filtering capabilities on non-ECS/custom fields. That said, some variants of runtime fields aren't fully supported between rules and alerts (see elastic/kibana#103587), so there are some dev dependencies to fulfill before we can document a complete workflow.
Runtime field support:
Tangential dev issues:
Metadata
Metadata
Assignees
Labels
Effort: LargeIssues that require significant planning, research, writing, and testingIssues that require significant planning, research, writing, and testingPriority: LowIssues that need attention, but are not urgentIssues that need attention, but are not urgentTeam: Detections/ResponseDetections and ResponseDetections and ResponseTeam: Docsv8.2.0