Skip to content

[Security Solution][Attacks/Alerts][Setup and miscellaneous] alert document mapping change #234095

@PhilippeOberti

Description

@PhilippeOberti

Summary

We need to add a new field on the alert document to be able to store attack ids.
See this internal RFC

Acceptance criteria

  • should have a field available for us to know which attack(s) an alert belongs to

Questions

  • Are we sure this is the direction we want to take?
  • What should we name this new field?

Metadata

Metadata

Labels

Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Threat Hunting Investigations Team

Type

No fields configured for Task.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions