Add event_data to common template so elastalert/playbook event_data fields can be indexed and searchable

This commit is contained in:
Wes Lambert
2021-05-03 17:03:30 +00:00
parent da19df5174
commit 619402cc67

View File

@@ -228,7 +228,11 @@
"event":{
"type":"object",
"dynamic": true
},
},
"event_data":{
"type":"object",
"dynamic": true
},
"file":{
"type":"object",
"dynamic": true