Add RFC for extended entity fields#2598
Conversation
Introduce a 9.4 strawperson RFC for new entity attributes, lifecycle, and relationship leaves, and propose enabling entity.risk reuse for normalized entities. Made-with: Cursor
🤖 GitHub commentsExpand to view the GitHub comments
Just comment with:
|
- Add stage-0 header comments and link to RFC 0049 - Merge entity-type guidance into Fields table; keyword (list) for arrays - Document flat relationship object shape and Field Re-use nesting - Fix entity.last_seen_timestamp reference; restore administered_by row - Match People, Source data, References, and Concerns style to other RFCs - Update usage example entity.type to array form Made-with: Cursor
chemamartinez
left a comment
There was a problem hiding this comment.
LGTM! My review is mostly focused on conversation's I've been involved and from an integration perspective so please wait for the rest of reviewer's approval.
trisch-me
left a comment
There was a problem hiding this comment.
lgtm in general with some minor feedback
Co-authored-by: Alexandra Konrad <alexandra.konrad@elastic.co>
Co-authored-by: Alexandra Konrad <alexandra.konrad@elastic.co>
Co-authored-by: Alexandra Konrad <alexandra.konrad@elastic.co>
Co-authored-by: Alexandra Konrad <alexandra.konrad@elastic.co>
Co-authored-by: Alexandra Konrad <alexandra.konrad@elastic.co>
…m/uri-weisman/ecs into entity_fields_9_4_rfc_strawperson
|
@andrewkroh can I please ask you to have a second look? |
|
We decided to wait with follow up PRs that utilize the fields defined in this RFC until it's merged Can I get another reviewer with write access to be able to merge this one? @trisch-me asking for your assistance. |
|
@taylor-swanson @andrewkroh could you check this out? |
|
Thanks everyone, @trisch-me I need your assistance with pushing this one? |
|
@uri-weisman can you create a follow up PR with fields put into yaml files? Or do you need help with it? |
Will create one, thanks! |
@uri-weisman Is the PR already in? We want to make sure the ECS fields are added in before we make changes to our integrations, so we can reduce future friction or potential breaking changes for users. |
|
Hey @narph, IIUC @trisch-me is working on introducing the follow up PR - ticket. |
|
hey @narph - the PR is there, but actual fields are not yet in ECS, I was going to introduce them, but there is a technical question I need to solve first, I hope it will be ready soon |
@narph, just as a heads up, the dynamic ECS templates in elasticsearch won't be updated until the next stack release, so any new fields that don't already match the dynamic template won't map properly if relying on that method. Looking at the list of fields, |
Summary
entity.attributes.*,entity.lifecycle.*, andentity.relationships.*leavesentity.risk.*reuse underentityfor normalized entity-level risk