-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Labels
Description
We've been experiencing a number of user issues (via discuss and SDH) that involve problems they're having when trying to use non ECS-compatible data/data sources with the Security App. I think we need add a more explicit notice of this requirement in our docs.
Today, we have a clear message in the Advanced Settings page. "Important: Elastic Security requires ECS-compliant data. If you use third-party data collectors to ship data to Elasticsearch, the data must be mapped to ECS. Elastic Security ECS field reference lists ECS fields used in Elastic Security."
Can we repeat this message in a prominent location on one or more or all of these more prominent pages?
- Overview page
- System Requirements page
- Ingest data to Elastic Security page (already has a good note about third-party collectors)
https://elastic.slack.com/archives/C013W8WME2Z/p1604498907006900