elastic / elastic/ecs

Missing schema for device

Open
#448 8 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
1.1k
Forks
455
Avg merge
17h 8m
Merged PRs (30d)
5

Description

Can you please add a core schema for device so that more details about a source device can be mapped to fields.

Some examples of where device might fit in are: switches, routers, wifi , phone or any other type of electronic device that routes traffic or uses a network for communication.

Examples of fields would be:

device.name
device.id
device.os.*
device.geo.* extensions of geo
device.ip* extensions of ip
device.mac.address
device.type
possibly a few other fields with a core of device.

If you have any suggestions on what I could use in place of device that might still fit within the existing or any planned future ECS schema let me know.

Thank you in advance for your consideration and reply

Contributor guide

Open the contributing guide

Research direction

Review the existing and planned ECS schemas to determine whether a device entity fits their field conventions. The issue does not identify files, tests, or an agreed field set; done would require a decided core schema and its accepted device fields.

Written by the indexing model from the issue text.

Assessment

Domain
backend-api-design
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.