From 01a46d94ead90da9604500f1341466f4dee55b87 Mon Sep 17 00:00:00 2001 From: Brandon Myers Date: Mon, 10 Jun 2019 18:03:27 -0500 Subject: [PATCH] Add alerts-* index mapping for docker environment --- .../mozdef_bootstrap/files/index_mappings/alerts-star.json | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 docker/compose/mozdef_bootstrap/files/index_mappings/alerts-star.json diff --git a/docker/compose/mozdef_bootstrap/files/index_mappings/alerts-star.json b/docker/compose/mozdef_bootstrap/files/index_mappings/alerts-star.json new file mode 100644 index 00000000..410286e4 --- /dev/null +++ b/docker/compose/mozdef_bootstrap/files/index_mappings/alerts-star.json @@ -0,0 +1,6 @@ +{ + "title": "alerts-*", + "timeFieldName": "utctimestamp", + "notExpandable": true, + "fields": "[{\"name\":\"_id\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_index\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":true,\"readFromDocValues\":false},{\"name\":\"_score\",\"type\":\"number\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_source\",\"type\":\"_source\",\"count\":0,\"scripted\":false,\"searchable\":false,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"_type\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":true,\"readFromDocValues\":false},{\"name\":\"category\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"notify_mozdefbot\",\"type\":\"boolean\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":true,\"readFromDocValues\":true},{\"name\":\"severity\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"summary\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"tags\",\"type\":\"string\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":false,\"readFromDocValues\":false},{\"name\":\"utctimestamp\",\"type\":\"date\",\"count\":0,\"scripted\":false,\"searchable\":true,\"aggregatable\":true,\"readFromDocValues\":true}]" +} \ No newline at end of file