Graph, observed data in flyouts, and likely additional security solution flows will require translation layers in both directions (entity->event log, log->entity).
The following is a list of layers that should be exposed to our internal clients:
- ESQL
- LLM
- KQL / DSL
- TypeScript
- Painless
Graph, observed data in flyouts, and likely additional security solution flows will require translation layers in both directions (entity->event log, log->entity).
The following is a list of layers that should be exposed to our internal clients: