Skip to content

[Docs][SIEM] 7.7 detection rule updates#974

Merged
benskelker merged 12 commits intoelastic:masterfrom
benskelker:rule_updates_7.7
Apr 8, 2020
Merged

[Docs][SIEM] 7.7 detection rule updates#974
benskelker merged 12 commits intoelastic:masterfrom
benskelker:rule_updates_7.7

Conversation

@benskelker
Copy link
Copy Markdown
Contributor

@benskelker benskelker commented Apr 2, 2020

Updates the docs with added detections functionality.

Preview

@benskelker benskelker mentioned this pull request Apr 2, 2020
10 tasks
@benskelker benskelker marked this pull request as ready for review April 6, 2020 09:12
@FrankHassanabad FrankHassanabad requested a review from rylnd April 6, 2020 14:31
Copy link
Copy Markdown

@rylnd rylnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ML Rule additions and Rule creation changes LGTM! Note that screenshots and a few references to the ML popover are going to be outdated once #62396 is merged, though.

Copy link
Copy Markdown

@dhurley14 dhurley14 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Had one comment but other than that LGTM!

For users with the `ml_admin` role, the `Anomaly Detection` interface within
the main navigation header can be used for for viewing, starting, and stopping
SIEM machine learning jobs.
For users with the `machine_learning_admin` role, the `ML job settings`
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the distinction here as we've (myself at least 😅) been conflating the users/roles -- ml_admin is the user, with the roles being machine_learning_admin, machine_learning_user, etc.

TIP: This example is based on the
<<volume-shadow-copy-deletion-via-vssadmin, Volume Shadow Copy Deletion via VssAdmin>> prebuilt rule.

. Select the timeline template used when you send a signal created by the rule
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Docs render fine of course, but extra space here:

Suggested change
. Select the timeline template used when you send a signal created by the rule
. Select the timeline template used when you send a signal created by the rule

Copy link
Copy Markdown
Member

@spong spong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ran through the latest updates and everything looks good here -- thanks @benskelker! 🙂

@benskelker benskelker merged commit c913fae into elastic:master Apr 8, 2020
@benskelker benskelker deleted the rule_updates_7.7 branch April 8, 2020 09:36
benskelker added a commit to benskelker/stack-docs that referenced this pull request Apr 8, 2020
* starts rule updates

* starts ml rule type

* more create rules stuff

* rule types cont

* add cases kib space info

* rule monitoring

* monitor cont

* typo

* corrections and screenshots

* more screenshots

* updates rule failure note

* cleanup and remove api key requirement
benskelker added a commit to benskelker/stack-docs that referenced this pull request Apr 8, 2020
* starts rule updates

* starts ml rule type

* more create rules stuff

* rule types cont

* add cases kib space info

* rule monitoring

* monitor cont

* typo

* corrections and screenshots

* more screenshots

* updates rule failure note

* cleanup and remove api key requirement
benskelker added a commit that referenced this pull request Apr 8, 2020
* starts rule updates

* starts ml rule type

* more create rules stuff

* rule types cont

* add cases kib space info

* rule monitoring

* monitor cont

* typo

* corrections and screenshots

* more screenshots

* updates rule failure note

* cleanup and remove api key requirement
benskelker added a commit that referenced this pull request Apr 8, 2020
* starts rule updates

* starts ml rule type

* more create rules stuff

* rule types cont

* add cases kib space info

* rule monitoring

* monitor cont

* typo

* corrections and screenshots

* more screenshots

* updates rule failure note

* cleanup and remove api key requirement
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants