[Enhancement] Modify message
Description to include Alert rule names
#2447
Labels
enhancement
New feature or request
message
Description to include Alert rule names
#2447
Modify
message
Description to include Alert rule namesSummary
The ECS
message
field description should be updated to clarify that it is not only for syslog-style logs but should also contain the name of the corresponding security rule, alert, or incident when applicable.Motivation
Currently, the
message
field description primarily focuses on log events, describing it as the log message optimized for viewing. However, in security contexts, this field plays a critical role in surfacing key alerting information. Security detections, alerts, and incidents should populatemessage
with their corresponding rule name, alert title, or incident name to provide better visibility in Elastic Security.This enhancement will ensure a more consistent and meaningful use of the
message
field across security event sources.Detailed Design
message
match_only_text
Proposed Updated Description:
The text was updated successfully, but these errors were encountered: