You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Wildcard is a data type for Elasticsearch string fields introduced in Elasticsearch 7.9. Wildcard optimizes performance for queries using wildcards (*) and regex, allowing users to perform grep-like searches without the limitations of the existing text and keyword types.
ECS is supporting wildcards (RFC here) for the following fields:
There is an impact on indexing throughput (5% decrease on average) and storage (5% increase on average) based on our performance testing of wildcard fields.
With a set of security integrations GA'ing in 7.14, we will update these integrations to change keyword fields to wildcard in 7.14. Beats modules will not be updated to ensure existing Beats users are not impacted.
While working on the elastic/package-spec#63 I introduced a simple dependency management to import ECS field definitions (name, type, description) directly from ECS repository. I will try to enable this feature for some packages in elastic/integrations.
Wildcard is a data type for Elasticsearch string fields introduced in Elasticsearch 7.9. Wildcard optimizes performance for queries using wildcards (*) and regex, allowing users to perform grep-like searches without the limitations of the existing text and keyword types.
ECS is supporting wildcards (RFC here) for the following fields:
error
error.stack_trace
http
http.request.body.content
http.response.body.content
process
process.command_line
registry
registry.data.strings
url
url.full
url.original
url.path
There is an impact on indexing throughput (5% decrease on average) and storage (5% increase on average) based on our performance testing of wildcard fields.
With a set of security integrations GA'ing in 7.14, we will update these integrations to change keyword fields to wildcard in 7.14. Beats modules will not be updated to ensure existing Beats users are not impacted.
Integrations to be updated for 7.14
- [ ] auditd- [ ] OktaThe text was updated successfully, but these errors were encountered: