Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Additional event "message" properties #103358

Open
EvanGertis opened this issue Jun 24, 2021 · 2 comments
Open

Additional event "message" properties #103358

EvanGertis opened this issue Jun 24, 2021 · 2 comments
Labels
enhancement New value added to drive a business result Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Detection Rules Anything related to Security Solution's Detection Rules Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@EvanGertis
Copy link

Describe the feature:
Adding event properties to detections event.

i.e.

message.property_1
message.property_2
message.property_3

The user can select an property to add to the detection based on the fields available with the selected index for the detection.

Describe a specific use case for the feature:
An improved filtering for detections would allow the event "message" and having additional properties associated with the event.

@botelastic botelastic bot added the needs-team Issues missing a team label label Jun 24, 2021
@cybersecdiva cybersecdiva added enhancement New value added to drive a business result Feature:Detection Rules Anything related to Security Solution's Detection Rules Feature:Detection Alerts Security Solution Detection Alerts Feature labels Jun 24, 2021
@jportner jportner added Team:SIEM and removed needs-team Issues missing a team label labels Jun 29, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Sep 22, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Detection Rules Anything related to Security Solution's Detection Rules Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

5 participants