Skip to content

Conversation

@karenzone
Copy link
Contributor

Add Elastic Common Schema (ECS) to the glossary

@karenzone
Copy link
Contributor Author

karenzone commented Mar 22, 2019

Moving from a slack thread:

@webmat suggested:

"The Elastic Common Schema (ECS) defines a common set of fields, their datatype, and gives guidance on their correct usage. ECS is used to improve uniformity of event data ingested into Elasticsearch."

I like where this is heading. For the glossary, we need to define what ECS is, not what it does.

Copy link
Contributor

@lcawl lcawl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@webmat
Copy link

webmat commented Mar 22, 2019

Here's an attempt at what it actually is :-)

The Elastic Common Schema (ECS) is a document schema for Elasticsearch, for use cases such as logging and metrics. ECS defines a common set of fields, their datatype, and gives guidance on their correct usage. ECS is used to improve uniformity of event data coming from different sources.

Copy link

@webmat webmat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@karenzone karenzone merged commit 782d921 into elastic:master Mar 26, 2019
@karenzone karenzone deleted the add-ecs-def branch March 26, 2019 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants