Skip to content

Conversation

nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Jun 13, 2025

Partially addresses https://github.com/elastic/security-team/issues/12799. Inserts a note letting users know that they should not modify alert index mappings.

Previews:

Corresponding 9.x/Serverless PR: elastic/docs-content#1735 and elastic/docs-content#1957

Copy link

A documentation preview will be available soon.

Request a new doc build by commenting
  • Rebuild this PR: run docs-build
  • Rebuild this PR and all Elastic docs: run docs-build rebuild

run docs-build is much faster than run docs-build rebuild. A rebuild should only be needed in rare situations.

If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here.

Copy link
Contributor

@approksiu approksiu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@nastasha-solomon
Copy link
Contributor Author

Note to self: Before merge this PR, need to link to docs for adding runtime fields to rules. Will need to make this change to the 9.x/Serverless docs as well.
cc: @approksiu @yctercero

Copy link
Contributor

@yctercero yctercero left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gracias, gracias!

@nastasha-solomon
Copy link
Contributor Author

Note to self: Before merge this PR, need to link to docs for adding runtime fields to rules. Will need to make this change to the 9.x/Serverless docs as well.

Made 8.x changes in this PR and 9.x/Serverless changes in elastic/docs-content#1957.

Copy link
Contributor

@jmikell821 jmikell821 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One slight suggestion; otherwise good to go!

@nastasha-solomon nastasha-solomon enabled auto-merge (squash) June 27, 2025 19:45
nastasha-solomon added a commit to elastic/docs-content that referenced this pull request Jun 27, 2025
…ndices pt.2 (#1957)

Related to elastic/security-team#12799.
Updates note that lets users know that they should not modify alert
index mappings. Redirects them to runtime fields instead.

Corresponding 8.x PR: elastic/security-docs#6882
@nastasha-solomon nastasha-solomon merged commit a09754a into 8.x Jun 27, 2025
4 checks passed
mergify bot pushed a commit that referenced this pull request Jun 27, 2025
* First draft

* Add link to runtime fields

* apply to other areas

* remove s

* cleanup

* Update docs/reference/alert-schema.asciidoc

Co-authored-by: Janeen Mikell Roberts <[email protected]>

---------

Co-authored-by: Janeen Mikell Roberts <[email protected]>
(cherry picked from commit a09754a)
mergify bot pushed a commit that referenced this pull request Jun 27, 2025
* First draft

* Add link to runtime fields

* apply to other areas

* remove s

* cleanup

* Update docs/reference/alert-schema.asciidoc

Co-authored-by: Janeen Mikell Roberts <[email protected]>

---------

Co-authored-by: Janeen Mikell Roberts <[email protected]>
(cherry picked from commit a09754a)
@nastasha-solomon nastasha-solomon deleted the issue-12799-8.x branch June 27, 2025 20:13
nastasha-solomon added a commit that referenced this pull request Jun 27, 2025
* First draft

* Add link to runtime fields

* apply to other areas

* remove s

* cleanup

* Update docs/reference/alert-schema.asciidoc



---------


(cherry picked from commit a09754a)

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: Janeen Mikell Roberts <[email protected]>
nastasha-solomon added a commit that referenced this pull request Jun 27, 2025
* First draft

* Add link to runtime fields

* apply to other areas

* remove s

* cleanup

* Update docs/reference/alert-schema.asciidoc



---------


(cherry picked from commit a09754a)

Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: Janeen Mikell Roberts <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants