Merge pull request #6822 from Security-Onion-Solutions/fix/event_fields

Add event.acknowledged and event.escalated mappings
This commit is contained in:
weslambert
2022-01-10 16:14:45 -05:00
committed by GitHub

View File

@@ -291,6 +291,14 @@
},
"event": {
"properties": {
"acknowledged": {
"type": "boolean",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"action": {
"ignore_above": 1024,
"type": "keyword"
@@ -331,6 +339,14 @@
"end": {
"type": "date"
},
"escalated": {
"type": "boolean",
"fields": {
"keyword": {
"type": "keyword"
}
}
},
"hash": {
"ignore_above": 1024,
"type": "keyword"