Skip to content

index selected Strelka result fields #919

@mmguero

Description

@mmguero

The analytics team (via @sephthir) has asked me to index:

  • strelka.file.tree.node
  • strekla.file.tree.root
  • strelka.file.tree.parent

To allow them to build a tree of a given file scan. This issue tracks that request.

Indexing as:

  • filescan.tree.depth
  • filescan.tree.node
  • filescan.tree.parent
  • filescan.tree.root

Metadata

Metadata

Assignees

Labels

dashboardsRelating to Malcolm's OpenSearch Dashboards interfaceenhancementNew feature or requestopensearchRelating to Malcolm's use of OpenSearchpipelineRelating to carving (extraction) of files from traffic and the scanning of those files
No fields configured for Feature.

Projects

Status

Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions