elastic / elastic/integrations

mimecast: data streams' fields are all directly under `mimecast.*`

Open
#10,747 3 comments 0 reactions 0 assignees View on GitHub
breaking change enhancement Integration:mimecast mapping/pipeline issue Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

With the exception of the newly added message release logs data stream, all the mimecast data stream place their custom fields directly under the `mimecast.*` group. We should consider moving these to `mimecast..*` for each. This would be a breaking change since users may be using those fields for current rules and so on.

ref: #10732

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.