One bug left: I want the fields host.name, user.name and host.ip are included in the returned alarm data. But these fields aren't filled with data, even when the actual event does have these fields.
note: possibly this bug comes from the fact that it also queries ES docs that have not yet been enriched. So include the search query in the module to include tag: enriched_*
PR for issue #138
One bug left: I want the fields
host.name
,user.name
andhost.ip
are included in the returned alarm data. But these fields aren't filled with data, even when the actual event does have these fields.