Skip to content

[REQUEST]: Document Process for Adding Non-ECS Fields to Attack Discovery Field Selection #534

Closed
@dhru42

Description

@dhru42

Description

What: We need to document the workflow for adding non-ECS fields to Attack Discovery's field selection. The documentation should explain how users can select alerts containing desired non-ECS fields, access the field selector through the chat button, and confirm that these fields become available in the settings UI for future use.

Resources

Link: https://elastic.slack.com/archives/C05BAPPP5KP/p1740063935545129?thread_ts=1739564182.445399&cid=C05BAPPP5KP

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

Identical

What release is this request related to?

N/A

Collaboration model

The documentation team

Point of contact.

Main contact: @jamesspi @dhru42 @andrew-goldstein

Stakeholders:

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions