Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Request] improved ES|QL investigation(highlighted) fields #5054

Closed
vitaliidm opened this issue Apr 5, 2024 · 2 comments
Closed

[Request] improved ES|QL investigation(highlighted) fields #5054

vitaliidm opened this issue Apr 5, 2024 · 2 comments
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Small Issues that can be resolved quickly Feature: ES|QL Feature: Rules Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine v8.14.0

Comments

@vitaliidm
Copy link
Contributor

Description

allows to select custom created fields in ES|QL query as investigation(highlighted) fields
shows only ES|QL fields for aggregating queries
shows ES|QL fields + index fields for non-aggregating queries. Since results are enriched with source documents in that case

Background & resources

Which documentation set does this change impact?

ESS only

ESS release

8.14

Serverless release

N/A

Feature differences

Available only on ESS

API docs impact

No impact on API

Prerequisites, privileges, feature flags

N/A

@jmikell821 jmikell821 added Docset: ESS Issues that apply to docs in the Stack release v8.14.0 Feature: ES|QL labels Apr 10, 2024
@nastasha-solomon nastasha-solomon added Team: Detection Engine Priority: High Issues that are time-sensitive and/or are of high customer importance Effort: Small Issues that can be resolved quickly Feature: Rules labels May 5, 2024
@nastasha-solomon
Copy link
Contributor

Note to self: I'll need to update the Serverless ES|QL rule docs once merge https://github.com/elastic/staging-serverless-security-docs/pull/340. Can re-use the ESS changes I'm adding in #5182.

@nastasha-solomon
Copy link
Contributor

ESS and Serverless docs are updated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Small Issues that can be resolved quickly Feature: ES|QL Feature: Rules Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine v8.14.0
Projects
None yet
Development

No branches or pull requests

3 participants