Skip to content

ECS Standard index names #313

Closed
Closed
@yoda-sec

Description

@yoda-sec

I looked through the ECS repo and other open issues and wasn't able to find anything related to index names. Does the ECS standard have any plans to define index naming conventions to make it easier to correlate similar types of data from different data sources? For example, if I am researching user authentication events for "jsmith", I may want to review audit logs from windows, linux, VPN, MFA, O365, etc and would typically want to start with 1 Kibana query or 1 dashboard that gives me information from all those data sources.

Is there any plan to "map" these types of events to a standard "audit" index or at-least to a standard device type index to make it easier to share alerting and visualization resources across the elastic user base?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions