-
Notifications
You must be signed in to change notification settings - Fork 518
Open
Labels
Category: MaintenanceCategory: Maintenance used for SI planningCategory: Maintenance used for SI planningIntegration:crowdstrikeCrowdStrikeCrowdStrikeTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Description
The plan for scaling CrowdStrike metadata enrichment is to use LOOKUP JOIN, first splitting the current fdr data stream into three: fdr, fdr_aidmaster and fdr_userinfo.
To aid this, the ingest pipeline needs to be clarified. Initial work has been done on that, identifying duplicated code and some small (inconsequential?) syntax issues.
Metadata
Metadata
Assignees
Labels
Category: MaintenanceCategory: Maintenance used for SI planningCategory: Maintenance used for SI planningIntegration:crowdstrikeCrowdStrikeCrowdStrikeTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request