Graylog2 / Graylog2/illuminate-documentation

Clarify event_action definition

Open
#120 0 comments 0 reactions 0 assignees View on GitHub
documentation triaged
Dominant language
HTML
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

**Please describe what you are requesting**
Clarify event_action documentation for schema

**Describe what change you are proposing**
Add a note for how to handle sources that provide an intended/configured action and the action that was actually taken (e.g., SEPM) and that the actual action should be mapped to event_action.

Contributor guide

Open the contributing guide

Research direction

Locate the schema documentation for event_action and review its current definition. Add guidance covering sources with intended or configured actions alongside the action actually taken, using the actual action as the mapped event_action; confirm the note matches the surrounding documentation.

Written by the indexing model from the issue text.

Assessment

Tech stack
html
Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.