In detection engine we do not add the ECS extended fields as part of the mapping such as parts of the transaction ones:
However, if you want them indexed you can add them either directly or better yet to the template so that any newly created indexes from the ILM policy will take effect.
You can change the template/mapping to whichever space you want to and then any newly created data will be indexed from that point forward from that space. You can create different template indexing and life cycle management policies per each space you want to as well since siem signals are per space.
To see the ILM policy, the current mapping, and the current template for the
default space from dev tools would be this:
If you are using another space such as "test-space", then replace ".siem-signals-default" with ".siem-signals-test-space" to see the settings for that space above.
To change any of the settings such as the template for newly created indexes when a roll over occurs and then the existing mapping you can do from dev tools using these references:
I don't know how sensitive your current data set is, or your production environment so I have to suffix all of this with please backup your siem signals, templates, mappings, etc... before doing any of these operations in case you need to "roll back" any changes and feel comfortable with the tooling:
On upgrades our product if you go this route, you just have to be cautious as we might migrate the indexes for you forward but we will keep in mind that advanced users might have "hand edited" some of these settings. So on future upgrades you will just want to double check that your custom mappings have rolled forward with our product or not and perform regular backups of your data using snapshots.