Scripted Fields are not supported by SIEM Detections Rules #97778
Labels
enhancement
New value added to drive a business result
Feature:Detection Alerts
Security Solution Detection Alerts Feature
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
Team:Detection Engine
Security Solution Detection Engine Area
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Team:SIEM
Kibana version:
7.12.0
Elasticsearch version:
7.12.0
Server OS version:
Ubuntu Focal 20.04 LTS
Original install method (e.g. download page, yum, from source, etc.):
Docker
Describe the bug:
Currently when creating detection rules in SIEM, scripted fields are not supported.
Steps to reproduce:
Expected behavior:
Scripted fields to be supported by SIEM
The text was updated successfully, but these errors were encountered: