Skip to content

[Detection Rules] Add 7.15 rules#111464

Merged
brokensound77 merged 2 commits intoelastic:masterfrom
brokensound77:detection-rules/7.15-14660994d2a
Sep 8, 2021
Merged

[Detection Rules] Add 7.15 rules#111464
brokensound77 merged 2 commits intoelastic:masterfrom
brokensound77:detection-rules/7.15-14660994d2a

Conversation

@brokensound77
Copy link
Copy Markdown
Contributor

Summary

Pull updates to detection rules from https://github.com/elastic/detection-rules/tree/v7.15.0.

Checklist

Delete any items that are not applicable to this PR.

@brokensound77 brokensound77 added v8.0.0 release_note:skip Skip the PR/issue when compiling release notes auto-backport Deprecated - use backport:version if exact versions are needed v7.15.0 v7.16.0 labels Sep 7, 2021
@brokensound77 brokensound77 requested a review from a team as a code owner September 7, 2021 21:05
"timestamp_override": "event.ingested",
"type": "query",
"version": 4
"version": 3
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is okay, because this v4 of the rule has never made it in a released stack

"license": "Elastic License v2",
"max_signals": 10000,
"name": "Endpoint Security Behavior Protection",
"query": "event.kind:alert and event.module:(endpoint and not endgame) and event.code: behavior\n",
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we removed this rule from the detection-rules repository, same reason as the other

@brokensound77 brokensound77 enabled auto-merge (squash) September 7, 2021 21:08
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@brokensound77 brokensound77 merged commit b8acf0f into elastic:master Sep 8, 2021
kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Sep 8, 2021
kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Sep 8, 2021
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 Backport successful

Status Branch Result
7.15
7.x

The backport PRs will be merged automatically after passing CI.

kibanamachine added a commit that referenced this pull request Sep 8, 2021
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
kibanamachine added a commit that referenced this pull request Sep 8, 2021
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
jloleysens added a commit to jloleysens/kibana that referenced this pull request Sep 8, 2021
…-link-to-kibana-app

* 'master' of github.com:elastic/kibana: (61 commits)
  [Logs UI] Fix alert previews for thresholds of `0` (elastic#111150)
  [Archive Migration][Partial] discover apps-discover (elastic#110437)
  [APM] Set start date of APM ML job to -4 weeks (elastic#111375)
  [ML] APM Latency Correlations: Code consolidation. (elastic#110790)
  [Discover] Fix indices permission for multiline test (elastic#111284)
  [Detection Rules] Add 7.15 rules (elastic#111464)
  [Security Solution][Endpoint][Host Isolation] Hide isolate host option in alert details rather than disabling (elastic#111064)
  React version of angular license view (elastic#111317)
  [APM] Fix link in readme (elastic#111362)
  [Security Solution] add agent field to generator (elastic#111428)
  [Dashboard] Retain Tags on Quicksave (elastic#111015)
  Reorder App Search ingestion methods (elastic#111361)
  Port performance docs to new docs system. (elastic#111063)
  [Security Solution][RAC] Fixes updatedAt loading bug (elastic#111010)
  [sample data] update web log geo.src field to match country code of geo.coordinates (elastic#110885)
  [Security solution] [Endpoint] Fix bad artifact migration (elastic#111294)
  Fix copy typo. (elastic#111203)
  [build] Remove empty optimize directory (elastic#111393)
  [Maps] fix term join not updating when editing right field (elastic#111030)
  [Fleet] Set default settings in component template instead of the index template (elastic#111197)
  ...

# Conflicts:
#	x-pack/plugins/reporting/public/management/__snapshots__/report_listing.test.tsx.snap
#	x-pack/plugins/reporting/public/management/report_listing.test.tsx
chrisronline pushed a commit to chrisronline/kibana that referenced this pull request Sep 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Deprecated - use backport:version if exact versions are needed release_note:skip Skip the PR/issue when compiling release notes v7.15.0 v7.16.0 v8.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants