Docs
  • Guides
  • APIs (opens in a new tab)
  • Products
    Elasticsearch Observability Security Elastic Cloud
  • Reference
  • Troubleshoot
  • Release notes
  1. Docs /
  2. Reference /
  3. Security

Fields and object schemas for Elastic Security

This reference section provides details on the fields Elastic Security uses to display data in the UI and Elastic Security JSON object schemas:

  • ECS fields required or used to analyze and display data
  • Timeline object schema
  • Alert schema
Previous
Security
Next
Elastic Security ECS field reference
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
Section
Reference
Docs Guides APIs (opens in a new tab)
Products
Elasticsearch Observability Security Elastic Cloud
Reference Troubleshoot Release notes
Version
Reference
  • Security
    • Fields and object schemas
      • Elastic Security ECS field reference
      • Timeline schema
      • Alert schema
    • Endpoint command reference
    • Elastic Defend advanced settings
    • Prebuilt detection rules reference
Elastic logo
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© 2026 Elasticsearch B.V. All Rights Reserved.

This content is available in different formats for convenience only. All original licensing terms apply.

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries. Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.