Please tell me, is it possible to take information from the "investigate in timeline" elastic security alert, which is located in the Inspect->Request tab?
Or maybe it is possible to universally convert the request received from /api/detection_engine/signals/search to DSL?
I want to receive this, maybe via api, knowing the _id of the document elastic security alert. Is it possible to receive this somehow not through the Kibana web interface?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.