Edwin AI Platform
Event Intelligence Dashboard Enhancements
The Event Intelligence dashboard in Edwin AI Dashboards has been reconfigured to highlight critical information.
To access this feature, navigate to Edwin AI > Dashboards. Select the Event Intelligence dashboard from the table.
Delimited Key-Value String Field Mapping Transformation
Edwin now provides additional field mapping transformations for normalizing event data received from third-party integrations. These transformations enhance flexibility when mapping vendor-specific fields and enrichment data to Edwin events, reducing the need for integration-specific ingestion logic.
The following field mapping transformations are now supported:
- Delimited Key-Value String (
DELIMITED_KV_STRING)—Parses delimited key-value strings, such as tags or labels, and maps the resulting values to event enrichments. - Copy (
COPY)—Copies a value from one field to another, enabling vendor-specific fields to be mapped to the corresponding Edwin field. The source field can optionally be removed after the value is copied. - String Transform (
STRING_TRANSFORM)—Normalizes string values during field mapping. Supported operations include trimming whitespace, converting values to uppercase or lowercase, and replacing literal string values. - Key Alias (
KEY_ALIAS)—Renames multiple enrichment keys using a configurable mapping, making it easier to standardize vendor-specific enrichment names to a consistent schema.
Transformations can be configured per integration through the existing fieldMappings configuration and applied in sequence, enabling multiple transformations to be combined when normalizing incoming events.
The existing JSON_ARRAY, VALUE, and DATETIME field mapping types continue to be supported.
Elasticsearch Log Queries in Edwin AI
You can now query Elasticsearch logs through the Elastic MCP server using the conversational agent or automatically during AI Investigations.
In AI Investigations, relevant Elastic log findings are surfaced in the AI Log Summary section.
For more information, see Edwin AI Investigation in product documentation.
Resolved an issue where SES email actions in Edwin AI sent repeated verification emails to identities with verification already pending. Email identities pending verification no longer receive additional verification emails when this action executes.
Resolved an issue where connectivity tests in ServiceNow developer instances failed to authenticate. Connectivity tests now ensure integration tests explicitly target and execute against the provided integration record.
Resolved an issue where a deleted integration continued to appear in Edwin AI integration settings. Deleted integrations are now removed from the page without requiring a refresh.


