Skip to content

[DOCS] Add new EQL search configuration options #2018

@joepeeples

Description

@joepeeples

Description

When creating a new event correlation detection rule, there are three new configuration options for EQL queries (per elastic/kibana#132247):

  • Event category field - Allows user to modify the categorization field to classify different types of events
  • Tiebreaker field - Used to sort hits with the same timestamp in ascending order
  • Timestamp field - Controls how documents are sorted within the result set

Checklist

Screenshot

Screenshot 2022-05-16 at 15 40 12

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions