[Mimecast] Add event.kind: alert
to parse alert data
#12600
Labels
enhancement
New feature or request
Integration:mimecast
Mimecast
Team:Service-Integrations
Label for the Service Integrations team
Add
event.kind: alert
to Parsed Data for Mimecast IntegrationDescription
Currently, the Mimecast integration does not include
event.kind: alert
in the parsed data mapped to ECS. As a result, alerts are not visible in Kibana sinceevent.kind: alert
is a required field for External Alerts. Whileevent.module
is correctly mapped,event.kind: alert
is missing.At the moment, the only values assigned to
event.kind
are:event
enrichment
pipeline_error
Impact
Proposed Solution
event.kind: alert
is correctly assigned to relevant Mimecast alert events.event.kind
andevent.module
.Acceptance Criteria
event.kind: alert
is correctly mapped for all relevant Mimecast alerts.event.kind: alert
.The text was updated successfully, but these errors were encountered: