Skip to content

[WIP] [DOCS] Update EQL docs for default event type and timestamp fields #53027

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 3 commits into from
Closed

[WIP] [DOCS] Update EQL docs for default event type and timestamp fields #53027

wants to merge 3 commits into from

Conversation

jrodewig
Copy link
Contributor

@jrodewig jrodewig commented Mar 2, 2020

Updates several references to the default event type (event_type) and
timestamp (timestamp) fields for the EQL search API throughout the EQL
docs.

Also updates EQL example log data to better align with the default fields.

Depends on #53004.

Updates several references to the default event type (`event_type`) and
timestamp (`timestamp`) fields for the EQL search API throughout the EQL
docs. Also updates EQL example log data to better align with the default
fields.
@jrodewig jrodewig added >docs General docs changes :Analytics/EQL EQL querying labels Mar 2, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-docs (>docs)

@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-search (:Search/EQL)

@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 2, 2020

CI is expected to fail until #53004 is merged.

@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 2, 2020

@elasticmachine update branch

@elasticmachine
Copy link
Collaborator

merge conflict between base and head

@costin
Copy link
Member

costin commented Mar 2, 2020

@jrodewig Please wait a bit - there are discussions on changing event_type to event.category and it's likely the same will happen for @timestamp.

See #52941

@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 2, 2020

Sounds good. I'll keep this PR as a draft until #52941 is sorted out. Thanks @costin.

@jrodewig jrodewig changed the title [DOCS] Update EQL docs for default event type and timestamp fields [WIP] [DOCS] Update EQL docs for default event type and timestamp fields Mar 2, 2020
@jrodewig
Copy link
Contributor Author

jrodewig commented Mar 3, 2020

Closed due to #53073. Will open another PR related to that one.

@jrodewig jrodewig closed this Mar 3, 2020
@jrodewig jrodewig deleted the docs__eql-search-docs-updates branch March 3, 2020 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Analytics/EQL EQL querying >docs General docs changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants