elastic / elastic/integrations
mimecast: data streams' fields are all directly under `mimecast.*`
Open
breaking change
enhancement
Integration:mimecast
mapping/pipeline issue
Team:Security-Service Integrations
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
With the exception of the newly added message release logs data stream, all the mimecast data stream place their custom fields directly under the `mimecast.*` group. We should consider moving these to `mimecast..*` for each. This would be a breaking change since users may be using those fields for current rules and so on.
ref: #10732
Contributor guide
Assessment
This issue has not been assessed yet.