[Security Solution][Detections][Threshold Rules] Add threshold_result to alert notification context (#95354)

* Don't remove threshold_result from _source prematurely

* Fix type error

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
This commit is contained in:
Madison Caldwell 2021-04-01 09:58:54 -04:00 committed by GitHub
parent 6238ef7bad
commit 9c5641dbd7
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -73,11 +73,12 @@ export const buildBulkBody = ({
...buildSignal([doc], rule),
...additionalSignalFields(doc),
};
// @ts-expect-error @elastic/elasticsearch _source is optional
delete doc._source.threshold_result;
const event = buildEventTypeSignal(doc);
const { threshold_result: thresholdResult, ...filteredSource } = doc._source || {
threshold_result: null,
};
const signalHit: SignalHit = {
...doc._source,
...filteredSource,
'@timestamp': new Date().toISOString(),
event,
signal,