-
Notifications
You must be signed in to change notification settings - Fork 203
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support for Provider_name
and Data[x]
notation to the field mapping
#1350
Comments
Provider_name
and Data[x]
notation to the field mapping functionProvider_name
and Data[x]
notation to the field mapping
Specification memo:
|
I have looked into the feasibility of implementation and it does not appear to be easy to achieve 🤔
@YamatoSecurity |
@fukusuket I see, sure, we can hold off on the implementation for now. I'm thinking it might be better to save the |
Sorry many times, I looked into it more and found how to implement this just now(though my current implementation is even more complicated...😇). I'll create PR. I see, It would be nice if eliminating Array would make it easier to integrate with things like ElasticSearch :) |
Currently, the field mapping feature does not support following point:
Provider_name
matchingProvider_names
, we need to convert the field value only when theProvider_name
matches.(in addition toChannel
,EventID
)Data[x]
notation filed mappingWe want to support following rule/field conversion, so I'll implement above point.
The text was updated successfully, but these errors were encountered: