Graylog2 / Graylog2/illuminate-documentation
Clarify event_action definition
- Dominant language
- HTML
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
**Please describe what you are requesting**
Clarify event_action documentation for schema
**Describe what change you are proposing**
Add a note for how to handle sources that provide an intended/configured action and the action that was actually taken (e.g., SEPM) and that the actual action should be mapped to event_action.
Contributor guide
Research direction
Locate the schema documentation for event_action and review its current definition. Add guidance covering sources with intended or configured actions alongside the action actually taken, using the actual action as the mapped event_action; confirm the note matches the surrounding documentation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- html
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100