Does anyone know if it's possible to create dashboards using the elastic common schema and not be restricted to logstash or filebeat logs?
We currently have the majority of our data comming in via logstash (logs-) however have just configured the AWS filebeat module for CloudTrail (filebeat-). I was wondering if it's possible to create dashboards based on ecs, such as a breakdown of all event.datasets we have or a simple count of logs over time based on ECS fields not just looking at top level indexes.
The other thing that i've been trying to do, which i know is not possible is create custom dashboard from the siem indexes. not sure the best place to raise that as a feature request as it would be really useful to be able to create dashboards for things such as which MITRE techniques are seen in detections and other metrics (mean time to resolve for example).