elastic / elastic/integrations

[elastic_agent]: Set `event.module` for all datasets in this integration

Open
#13,897 3 comments 0 reactions 0 assignees View on GitHub
Integration:elastic_agent needs:triage Team:Elastic-Agent
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Elastic Agent [elastic_agent]

### Dataset Name

All

### Integration Version

Latest

### Agent Version

Latest

### OS Version and Architecture

N/A

### User Goal

Many other integrations set the `event.module` field to indicate the integration name, especially when there are multiple datasets within an integration. User has alert rules setup based on the agent & module combination, though since this field is not populated, the alerts don't work the as as for other integrations. Ideal situation would be for `event.module` to be set to `elastic_agent` for all datasets within this integration.

### Existing Features

It possible to setup custom component templates, though as this integration has many data streams, it's a bit cumbersome to apply, and the current behavior is different from many other integrations that set a value out of the box.

### What did you see?

n/a

### Anything else?

This issue was raised by support on behalf of a customer.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.