Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Bundle Rule Monitoring dashboard with Rule Execution Log enhancements #112196

Open
spong opened this issue Sep 15, 2021 · 4 comments
Labels
enhancement New value added to drive a business result Feature:Detection Rules Security Solution rules and Detection Engine Feature:Rule Monitoring Security Solution Detection Rule Monitoring area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@spong
Copy link
Member

spong commented Sep 15, 2021

Similar to how the CTI folks started linking off to custom dashboards for Threat Intelligence (#100423), while we enhance our capabilities around Rule Monitoring, it would be nice if we could ship a Rule Monitoring dashboard similar to the great dashboard @pmuellr put together for better diagnosing Task Manager/Alerting issues.

Unlike the CTI dashboard PR above, which I believe was relying on dashboards being loaded as part of setting up the filebeat threat intel module, we'd need to provide the dashboard assets and corresponding KIPs (now DataViews), so this may be a little more effort than it's worth depending on our in-flight Rule Monitoring upgrades.

@spong spong added enhancement New value added to drive a business result Feature:Detection Rules Security Solution rules and Detection Engine Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Feature:Rule Monitoring Security Solution Detection Rule Monitoring area Team:Detection Rule Management Security Detection Rule Management Team labels Sep 15, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@pmuellr
Copy link
Member

pmuellr commented Sep 15, 2021

One of the issues with dashboards over system indices (.kibana*) is that normal users won't have read privs so the graphs come up empty, which is correct. So would need some doc indicating it only works for superusers or users who are given read privs, presumably via a new role, so that should all be documented. With the caveat that given read privs to those indices, the user can see any Kibana SO's in any spaces.

@spong
Copy link
Member Author

spong commented Sep 27, 2021

Linking Rule Monitoring POC #111452 (comment) -- if this ships as experimental in 7.16 there is less of a need to bundle this dashboard as an interim solution.

@MindyRS MindyRS added the Team:Detections and Resp Security Detection Response Team label Feb 23, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@banderror banderror changed the title [Security Solution][Detections] Bundle Rule Monitoring dashboard with Rule Execution Log enhancements [Security Solution] Bundle Rule Monitoring dashboard with Rule Execution Log enhancements Nov 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Detection Rules Security Solution rules and Detection Engine Feature:Rule Monitoring Security Solution Detection Rule Monitoring area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

4 participants