2. What is the difference between the Data views that the Logs Explorer view can handle and the ones that will be sent to Discover?
|
3. How can use create a Data View in this data selector?
4. How should we save integration information in the rule's saved object and what the API will look like?
Here is a comment with the result of the investigation during ON Week. Another idea that Jason mentioned was to save the integration always as an ad-hoc data view and save additional data for integration to be able to show it nicely in the UI. In that case, would the data view get out of sync with the integration?
Summary
During the discussion about the simplification of the custom threshold flyout, there was a suggestion to use the data selector from Logs Explorer. We tried using data selection from Logs Explorer in ON Week and there are some questions that we need to address before continuing that work.
Adjustments in the data selector
Questions
1. What does the uncategorized tab mean?
|
2. What is the difference between the Data views that the Logs Explorer view can handle and the ones that will be sent to Discover?
|
3. How can use create a Data View in this data selector?
4. How should we save integration information in the rule's saved object and what the API will look like?
Here is a comment with the result of the investigation during ON Week. Another idea that Jason mentioned was to save the integration always as an ad-hoc data view and save additional data for integration to be able to show it nicely in the UI. In that case, would the data view get out of sync with the integration?