Skip to content

[Internal]: Update Security Alert schema to include new fields #2673

@rylnd

Description

@rylnd

Description

What: Some new fields were added to the alerts schema: elastic/kibana#220447
When: These changes were shipped in 8.19/9.1.
Why: Documenting these fields will give users one more opportunity to leverage these fields and/or remove any workarounds they may have needed in the interim

Resources

The feature was implemented in elastic/kibana#220447.

It was discussed in both elastic/kibana#156060 and more recently in elastic/kibana#171104.

It is very similar to the kibana.alert.original_event.* fields, in that they are copied from the source event(s) to a new, custom location on the alert.

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

None.

What release is this request related to?

8.19

Serverless release

It's in there!

Collaboration model

The documentation team

Point of contact.

Main contact: @rylnd

Stakeholders: @yctercero @approksiu

Metadata

Metadata

Labels

Team:ExperienceIssues owned by the Experience Docs Team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions