Skip to content

[7.x] [Security Solution][Detections] Reduce detection engine reliance on _source (#89371)#90287

Merged
marshallmain merged 1 commit intoelastic:7.xfrom
marshallmain:backport/7.x/pr-89371
Feb 4, 2021
Merged

[7.x] [Security Solution][Detections] Reduce detection engine reliance on _source (#89371)#90287
marshallmain merged 1 commit intoelastic:7.xfrom
marshallmain:backport/7.x/pr-89371

Conversation

@marshallmain
Copy link
Copy Markdown
Contributor

Backports the following commits to 7.x:

…source (elastic#89371)

* First pass at switching rules to depend on fields instead of _source

* Fix tests

* Change operator: excluded logic so missing fields are allowlisted

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
@marshallmain marshallmain added the backport This PR is a backport of another PR label Feb 4, 2021
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@marshallmain marshallmain merged commit 7478b45 into elastic:7.x Feb 4, 2021
@marshallmain marshallmain deleted the backport/7.x/pr-89371 branch February 4, 2021 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants