Hi willemdh,
You just have to set ECS categorization field event.kind:"alert". To get full use of the "Stack by" functions on the overview and detections pages, also populate event.module and event.category. To get hyperlinks back to the source of alert, you can populate rule.reference with a URL.
Mike,
Actually the way you are describing how it works, is exactly how I was hoping it would work. I already started flagging event.Kind with Alert's some time ago, so this should play out perfect.
We will wait for 7.6.1 however before upgrading our PR cluster, but I will play with this functionality in our QA.
TX!
Willem
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.