elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
199 stars 429 forks source link

mimecast: data streams' fields are all directly under `mimecast.*` #10747

Open efd6 opened 2 months ago

efd6 commented 2 months ago

With the exception of the newly added message release logs data stream, all the mimecast data stream place their custom fields directly under the mimecast.* group. We should consider moving these to mimecast.<datastream>.* for each. This would be a breaking change since users may be using those fields for current rules and so on.

ref: #10732

elasticmachine commented 2 months ago

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)