Open jcger opened 2 years ago
Pinging @elastic/response-ops (Team:ResponseOps)
As of today, I do not think we really need to do anything here to go away from what elastic search do. However, we can always re-evaluate in the future.
siem seems to need it, reopenin
To make our life easier we'd like to have the fetch alerts api to be consistent and return all of their values the same way. Right now it returns an array for almost every field loaded, e.g _id and _index are not (see screenshot)
A possible solution could be returning every field as an array
This would allow us to not having to branch our code checking the type of the value in the alerts table cell render callback.