RedELK
RedELK copied to clipboard
Alarm manual
PR for issue #138
One bug left: I want the fields host.name, user.name and host.ip are included in the returned alarm data. But these fields aren't filled with data, even when the actual event does have these fields.
note: possibly this bug comes from the fact that it also queries ES docs that have not yet been enriched. So include the search query in the module to include tag: enriched_*