Skip to content

[7.x] [Security Solution][Detections] Modify threshold rule synthetic signal generation to use data from last hit in bucket (#82444)#83213

Merged
madirey merged 1 commit intoelastic:7.xfrom
madirey:backport/7.x/pr-82444
Nov 12, 2020
Merged

[7.x] [Security Solution][Detections] Modify threshold rule synthetic signal generation to use data from last hit in bucket (#82444)#83213
madirey merged 1 commit intoelastic:7.xfrom
madirey:backport/7.x/pr-82444

Conversation

@madirey
Copy link
Copy Markdown
Contributor

@madirey madirey commented Nov 11, 2020

Backports the following commits to 7.x:

…l generation to use data from last hit in bucket (elastic#82444)

* Fix threshold rule synthetic signal generation

* Use top_hits aggregation

* Add timestampOverride

* Account for when threshold.field is not supplied

* Ensure we're getting the last event when threshold.field is not provided

* Add missing import
@madirey madirey added the backport This PR is a backport of another PR label Nov 11, 2020
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@madirey madirey merged commit daf31f8 into elastic:7.x Nov 12, 2020
@madirey madirey deleted the backport/7.x/pr-82444 branch November 12, 2020 02:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants