Closed
Description
I looked through the ECS repo and other open issues and wasn't able to find anything related to index names. Does the ECS standard have any plans to define index naming conventions to make it easier to correlate similar types of data from different data sources? For example, if I am researching user authentication events for "jsmith", I may want to review audit logs from windows, linux, VPN, MFA, O365, etc and would typically want to start with 1 Kibana query or 1 dashboard that gives me information from all those data sources.
Is there any plan to "map" these types of events to a standard "audit" index or at-least to a standard device type index to make it easier to share alerting and visualization resources across the elastic user base?
Metadata
Metadata
Assignees
Labels
No labels