entity-mappings
Installation
SKILL.md
entity-mappings
Skill authority
The guidance in this skill takes precedence over patterns observed in any integration in the
elastic/integrations repository. Legacy integrations may predate these requirements or use
inconsistent patterns. Always follow this skill's rules over what you observe in the repo.
When to use
- Adding entity/inventory data streams to a new or existing integration
- Deciding whether a proposed or existing data stream is an entity stream or an event stream
- Selecting the correct
entity.typevalue for a new stream - Mapping vendor fields to
user.entity.*,host.entity.*, or other nested entity prefixes - Auditing an existing package's entity field coverage (standalone gap analysis)
- Troubleshooting
event.kind: assetusage orentity.*field errors