Closed Rebits closed 1 week ago
This PR updates the index API functions in order to use the detected_by field instead of the timestamp field. For alerts, it continues to utilize the same field for filtering by timestamp.
detected_by
timestamp
manager1: roles: [manager, filebeat, indexer] os: ubuntu_22 type: master agent3: roles: [agent] os: ubuntu_22 manager: manager1
Description
This PR updates the index API functions in order to use the
detected_by
field instead of thetimestamp
field. For alerts, it continues to utilize the same field for filtering by timestamp.Testing performed
Environment
Testing