elastic / elastic/integrations
[elastic_agent]: Set `event.module` for all datasets in this integration
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
### Integration Name
Elastic Agent [elastic_agent]
### Dataset Name
All
### Integration Version
Latest
### Agent Version
Latest
### OS Version and Architecture
N/A
### User Goal
Many other integrations set the `event.module` field to indicate the integration name, especially when there are multiple datasets within an integration. User has alert rules setup based on the agent & module combination, though since this field is not populated, the alerts don't work the as as for other integrations. Ideal situation would be for `event.module` to be set to `elastic_agent` for all datasets within this integration.
### Existing Features
It possible to setup custom component templates, though as this integration has many data streams, it's a bit cumbersome to apply, and the current behavior is different from many other integrations that set a value out of the box.
### What did you see?
n/a
### Anything else?
This issue was raised by support on behalf of a customer.
Contributor guide
Assessment
This issue has not been assessed yet.