Hi @Lradu,
The “detection_fields” field has not actually been deprecated. That warning will go away soon after a change is pushed out to customers.
Can you share the search query that returns results? Are you able to verify that these conditions are true in the events that you see after running the search? These conditions are in the community rule that you shared.
condition:
#gcp > 5 and #target_application > 1 and #product_event_type > 1
Hi @Lradu,
The “detection_fields” field has not actually been deprecated. That warning will go away soon after a change is pushed out to customers.
Can you share the search query that you’re using where results are returned? Are you able to verify that the following conditions are true in the events that you see. These conditions are in the community rule that you shared.
condition:
#gcp > 5 and #target_application > 1 and #product_event_type > 1
Thanks
Hi @David-French Indeed, the missing results were because I naively omitted the condition. :)
Thanks for the confirmation that the warning will go away soon.
Glad you figured it out, @Lradu!