Skip to content

Conversation

@jrodewig
Copy link
Contributor

@jrodewig jrodewig commented Mar 2, 2020

Updates several references to the default event type (event_type) and
timestamp (timestamp) fields for the EQL search API throughout the EQL
docs.

Also updates EQL example log data to better align with the default fields.

Depends on #53004.

Updates several references to the default event type (`event_type`) and
timestamp (`timestamp`) fields for the EQL search API throughout the EQL
docs. Also updates EQL example log data to better align with the default
fields.
@jrodewig jrodewig added >docs General docs changes :Analytics/EQL EQL querying labels Mar 2, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-docs (>docs)

@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-search (:Search/EQL)

@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 2, 2020

CI is expected to fail until #53004 is merged.

@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 2, 2020

@elasticmachine update branch

@elasticmachine
Copy link
Collaborator

merge conflict between base and head

@costin
Copy link
Member

costin commented Mar 2, 2020

@jrodewig Please wait a bit - there are discussions on changing event_type to event.category and it's likely the same will happen for @timestamp.

See #52941

@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 2, 2020

Sounds good. I'll keep this PR as a draft until #52941 is sorted out. Thanks @costin.

@jrodewig jrodewig changed the title [DOCS] Update EQL docs for default event type and timestamp fields [WIP] [DOCS] Update EQL docs for default event type and timestamp fields Mar 2, 2020
@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 3, 2020

Closed due to #53073. Will open another PR related to that one.

@jrodewig jrodewig closed this Mar 3, 2020
@jrodewig jrodewig deleted the docs__eql-search-docs-updates branch March 3, 2020 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

:Analytics/EQL EQL querying >docs General docs changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants