If an alert is an endpoint alert, there is an agent status row in the alert details. The values for that row show a draggable Agent status and Isolation status badge. Currently if a user were to drag these badges onto a new timeline, it would not filter anything because they are not available in the default indeces. We should add these two statuses to the elastic common schema so they are actually valid draggables and can be used to filter timelines.
If an alert is an endpoint alert, there is an agent status row in the alert details. The values for that row show a draggable
Agent status
andIsolation status
badge. Currently if a user were to drag these badges onto a new timeline, it would not filter anything because they are not available in the default indeces. We should add these two statuses to the elastic common schema so they are actually valid draggables and can be used to filter timelines.