Open benakansara opened 2 years ago
Pinging @elastic/actionable-observability (Team: Actionable Observability)
@elastic/response-ops-ram FYI
cc @vinaychandrasekhar How critical is it not to be able to search for alerts using labels?
@benakansara check mapping of labels field if it is enabled: false
The field
labels
is of typeobject
in the ECS and since we havedynamic: false
in the AAD index mapping, the subfields oflabels
are not added to the mapping. As a result, we are not able to use subfields of labels to filter alerts or correlate alerts.We experimented with the type and found that using
flattened
might be more suitable for this use case. Withflattened
type, we are able to query data with subfields. However, changing toflattened
will makelabels
field non ECS compliant.Our goal is to be able to search alerts using labels e.g.
labels.eventId
orlabels.groupId
.The search query below works with subfields when the type of the field is
flattened
. The same does not work withobject
type.