Motivation
Currently, having custom (non ECS) fields at the root level of vulnerability is a wrong doing
It can cause conflicts with other integrations
The proposed way for integrations having customized fields is to add them under the package name
In our case, cloud_security_posture.*
Definition of done
Out of scope
Related tasks/epics
Motivation
Currently, having custom (non ECS) fields at the root level of vulnerability is a wrong doing
It can cause conflicts with other integrations
The proposed way for integrations having customized fields is to add them under the package name
In our case,
cloud_security_posture.*Definition of done
type,class,cluster_idand make sure cloudbeat's events follow the specified guidelinekibana)Out of scope
Related tasks/epics