Skip to content

[Entity Analytics] Watchlist docs should mention that index pattern needs @timestamp field. #8097

Description

@ymao1

In the Watchlist docs, we should mention that for Rule Based Data Sources > Index Pattern, the selected index pattern must have the @timestamp field. Selecting an index pattern without a @timestamp field will cause no entities ever to be synced. On the Kibana side, we're adding validation to that field in the UI in elastic/kibana#287385

This has been a requirement since Watchlists were added in 9.4

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Team:SKIIssues owned by the SKI Docs Team

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions