Lots of unmapped fields in .siem-signals-default

That's not a bad idea. In the code we always look for .siem-signals-${space-id} such as .siem-signals-default within SIEM if that helps you out planning a strategy.

Happy to hear you're a very experienced beats person! :slight_smile: