-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feat/olm endpoint action responses update schemas epic 1279 #198
Feat/olm endpoint action responses update schemas epic 1279 #198
Conversation
in order to follow ECS convention
We are going to keep this until 8.0.0. And then remove them from base fields.
custom_subsets/elastic_endpoint/action_responses/action_responses.yaml
Outdated
Show resolved
Hide resolved
Thanks for the ping @ashokaditya . Since ECS leverages lowercase names for the definitions of the top level fields we chose to capitalize our fields to avoid potential conflicts. An example of a conflict would be if the ECS core team released a top level field called Seems like most fields in this PR don't really exist in ECS (except maybe Another thing we can do is if the fields we're adding make sense within a top level field that ECS already provides (but the exact field doesn't exist yet) we can extend the ECS top level field and place the new field under |
During the course of doing this mapping update, I did think about nesting "requests" and "responses" under a top-level field, so I'm going to go ahead and give that a try. 👍 Also, this way the mapping makes also more contextual sense.
Indeed! I'll keep that in mind.
This is also another good idea, but I think I'll rather wait and discuss this with @pzl before trying this out. |
review suggestion
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good 👍 thanks for making the changes.
custom_subsets/elastic_endpoint/action_responses/action_responses.yaml
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🐑 🚀 ?
Change Summary
Sample values
.logs-endpoint.actions
data streamexpand mapping
Sample document for
.logs-endpoint.action
data stream:Sample document with an error field:
Using API to add a single document to
.logs-endpoint.actions
data stream:.logs-endpoint.action.responses
data streamexpand mapping
Sample document for
.logs-endpoint.action.responses
data stream (that the endpoint writes to):Sample document with an error field
Using API to add a single document to
.logs-endpoint.action.responses
data stream:Release Target
v7.16
Q/A
For mapping changes:
make
after making the schema changes, and committed any generated files (inschema/
,generated/
)