-
Couldn't load subscription status.
- Fork 205
Closed
Labels
Docset: ESSIssues that apply to docs in the Stack releaseIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityIssues for Serverless SecurityEffort: SmallIssues that can be resolved quicklyIssues that can be resolved quicklyFeature: RulesPriority: HighIssues that are time-sensitive and/or are of high customer importanceIssues that are time-sensitive and/or are of high customer importanceTeam: Detection Enginev8.16.0
Description
Description
The kibana.alert.rule.execution.type field conveys whether an alert was created by a manual run or a scheduled run. With the introduction of this field, the kibana.alert.intended_timestamp field will now show the same value as the same as @timestamp field.
Misc. notes:
- The field can have two values:
manualorscheduled - The field type is...
- Will need to doc field in the alert schema table for Serverless and ESS. See Slack for how the
kibana.alert.intended_timestampfield description should be updated.
Background & resources
- PRs: Execution type field kibana#195884
- Issues/metas: https://github.com/elastic/security-team/issues/10459
- Point of contact: @nkhristinin @approksiu
- Test environments: TBD
Which documentation set does this change impact?
ESS and serverless
ESS release
8.16
Serverless release
Tuesday, October 22, 2024
Feature differences
N/A
API docs impact
TBD
Prerequisites, privileges, feature flags
N/A
Metadata
Metadata
Assignees
Labels
Docset: ESSIssues that apply to docs in the Stack releaseIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityIssues for Serverless SecurityEffort: SmallIssues that can be resolved quicklyIssues that can be resolved quicklyFeature: RulesPriority: HighIssues that are time-sensitive and/or are of high customer importanceIssues that are time-sensitive and/or are of high customer importanceTeam: Detection Enginev8.16.0