[Security Solution] [Detections] [Platform] Expose _tier
in the Security Solution
#130517
Labels
8.10 candidate
8.15 candidate
consider-next
enhancement
New value added to drive a business result
Feature:Detection Rules
Security Solution rules and Detection Engine
Feature:Hosts
Security Solution Hosts feature
Feature:Network
Security Solutions Network feature
Feature:SecurityOverview
Security Solution Overview feature
Feature:Timeline
Security Solution Timeline feature
Team:Detection Engine
Security Solution Detection Engine Area
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Currently (versions
<= 8.1
), if users want to segment data in the security solution between the different data tiers they have to rely on index aliases. By exposing the_tier
field in queries executed in the security solution, we can better provide users with finer-grained controls when searching for alerts and associated source events fromhot
,warm
,cold
,frozen
nodes.This issue will serve as a reference as work progresses towards this goal.
TODO:
The text was updated successfully, but these errors were encountered: