Elasticsearch connector: mapping custom date and time
After installing and configuring an integration, you need to map their fields to Google Security Operations fields in order to show the information in the platform.
When configuring the Elasticsearch connector, you need to convert or map the custom date and time, such as \_source\_@timestamps, to startTime and endTime of Google Security Operations cases.
- Navigate to SOAR Settings > Ontology > Ontology Status.
- Click settings Configure in the same row as the Elasticsearch connector.
- In the Event Configuration page, select Mapping.
- Under System Fields, select the StartTime row and choose Edit Field from the menu.
- In the Map Target Field: StartTime dialog:
- For Extracted Field, select \_source\_@timestamp, which is from the ELK stack.
- For Transformation Function, select FROM_CUSTOM_DATETIME from the menu.
-
In the Enter Parameters field, enter
YYYY-MM-DDTHH:MM:SS:zzzZ
. -
In the Map Target Field: EndTime dialog:
- For Extracted Field, select \_source\_@timestamp, which is from the ELK stack.
- For Transformation Function, select FROM_CUSTOM_DATETIME from the menu.
-
In the Enter Parameters field, enter
YYYY-MM-DDTHH:MM:SS:zzzZ
. This is to generalize the time format.
- Click Save.
The Elasticsearch timestamp fields are now converted to the standardized time and date fields.