You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/action_responses/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -155,10 +154,9 @@
155
154
fields:
156
155
- name: version
157
156
level: core
158
-
required: true
159
157
type: keyword
160
158
ignore_above: 1024
161
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
159
+
description: 'ECS version this event conforms to.
162
160
163
161
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/actions/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -161,10 +160,9 @@
161
160
fields:
162
161
- name: version
163
162
level: core
164
-
required: true
165
163
type: keyword
166
164
ignore_above: 1024
167
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
165
+
description: 'ECS version this event conforms to.
168
166
169
167
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/alerts/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -3241,10 +3240,9 @@
3241
3240
fields:
3242
3241
- name: version
3243
3242
level: core
3244
-
required: true
3245
3243
type: keyword
3246
3244
ignore_above: 1024
3247
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
3245
+
description: 'ECS version this event conforms to.
3248
3246
3249
3247
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/api/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -88,10 +87,9 @@
88
87
fields:
89
88
- name: version
90
89
level: core
91
-
required: true
92
90
type: keyword
93
91
ignore_above: 1024
94
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
92
+
description: 'ECS version this event conforms to.
95
93
96
94
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/collection/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -45,10 +44,9 @@
45
44
fields:
46
45
- name: version
47
46
level: core
48
-
required: true
49
47
type: keyword
50
48
ignore_above: 1024
51
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
49
+
description: 'ECS version this event conforms to.
52
50
53
51
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/file/fields/fields.yml
+1-4Lines changed: 1 addition & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -251,11 +250,9 @@
251
250
fields:
252
251
- name: version
253
252
level: core
254
-
required: true
255
253
type: keyword
256
254
ignore_above: 1024
257
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
258
-
255
+
description: 'ECS version this event conforms to.
259
256
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/library/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -454,10 +453,9 @@
454
453
fields:
455
454
- name: version
456
455
level: core
457
-
required: true
458
456
type: keyword
459
457
ignore_above: 1024
460
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
458
+
description: 'ECS version this event conforms to.
461
459
462
460
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/metadata/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -153,10 +152,9 @@
153
152
fields:
154
153
- name: version
155
154
level: core
156
-
required: true
157
155
type: keyword
158
156
ignore_above: 1024
159
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
157
+
description: 'ECS version this event conforms to.
160
158
161
159
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
Copy file name to clipboardExpand all lines: package/endpoint/data_stream/metrics/fields/fields.yml
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,5 @@
1
1
- name: '@timestamp'
2
2
level: core
3
-
required: true
4
3
type: date
5
4
description: 'Date/time when the event originated.
6
5
@@ -755,10 +754,9 @@
755
754
fields:
756
755
- name: version
757
756
level: core
758
-
required: true
759
757
type: keyword
760
758
ignore_above: 1024
761
-
description: 'ECS version this event conforms to. `ecs.version` is a required field and must exist in all events.
759
+
description: 'ECS version this event conforms to.
762
760
763
761
When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events.'
0 commit comments