Skip to content

[Response Ops][Alerting] Migrate installation of preview resources to framework alerts-as-data  #152490

@ymao1

Description

@ymao1

Security solutions currently uses the rule registry to install preview indices for detection rules. These are a set of indices that use the same mappings as normal alert indices but they use a different ILM policy that deletes the preview data within a day. As part of framework alerts as data, we'd like to migrate all resource installation out of the rule registry and into the alerting plugin so we either need to provide a specific way to install preview indices for any rule types or generic functions that can be called to install custom resources.

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions