Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bests preserve original format #20774

Closed
gwsales opened this issue Aug 25, 2020 · 2 comments
Closed

Bests preserve original format #20774

gwsales opened this issue Aug 25, 2020 · 2 comments

Comments

@gwsales
Copy link

gwsales commented Aug 25, 2020

Describe the enhancement:
Add a flag into various parsers to keep original formatting vs moving fields to the ECS format.

Describe a specific use case for the enhancement or feature:
Sometimes it is needed to keep the original event in an an unaltered state for compliance reasons.

#18526

This parser is great and very helpful for search and detection, but sometimes the original event is needed to be preserved. Please add a flag to preserve original event fields without requiring the full raw event to be stored in event.original.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Aug 25, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/siem (Team:SIEM)

@marc-gr marc-gr added enhancement and removed needs_team Indicates that the issue/PR needs a Team:* label labels Aug 25, 2020
@botelastic
Copy link

botelastic bot commented Jul 26, 2021

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@botelastic botelastic bot added the Stalled label Jul 26, 2021
@botelastic botelastic bot closed this as completed Aug 25, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants