You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, we save group-related fields at the root level in AAD depending on the group by field as described here.
Since group by field is an important field that can be used in various features such as maintenance window or conditional action to filter alerts, we would like to expand the above-mentioned logic to save the group by fields at the root level if they are ECS fields.
Implementation idea
We can create a shared function and pass all the group-by fields to this function and return only fields that are ECS-compliant, then we can use this logic in all the rules that have group-by functionality:
Custom threshold
Metric threshold
Log threshold
Inventory threshold
SLO burn rate
ES Query
Acceptance criteria
Create a shared logic to get the list of ECS-compliant group by fields and save that information at the root level of the alert document
The text was updated successfully, but these errors were encountered:
maryam-saeidi
changed the title
Save ECS group by fields at the root level
Save ECS group by fields at the root level of alerting document
May 12, 2024
Summary
Currently, we save group-related fields at the root level in AAD depending on the group by field as described here.
Since group by field is an important field that can be used in various features such as maintenance window or conditional action to filter alerts, we would like to expand the above-mentioned logic to save the group by fields at the root level if they are ECS fields.
Implementation idea
We can create a shared function and pass all the group-by fields to this function and return only fields that are ECS-compliant, then we can use this logic in all the rules that have group-by functionality:
Acceptance criteria
The text was updated successfully, but these errors were encountered: