-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security solution to onboard alert summaries and report the alerts 1:1 to the platform #147379
Labels
Feature:Alerting/RulesFramework
Issues related to the Alerting Rules Framework
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
Comments
Pinging @elastic/response-ops (Team:ResponseOps) |
This was referenced Dec 20, 2022
ymao1
added a commit
that referenced
this issue
Dec 21, 2022
Towards #147379 ## Summary When investigating how to [onboard detection alerts onto framework alert summaries](#147379), there were some discrepancies in the format of the alert documents returned. This PR fixes the formatting so it matches and there will be no difference in `context.alerts` when we migrate detection alerts to the framework. ### Checklist - [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios
simianhacker
pushed a commit
to simianhacker/kibana
that referenced
this issue
Dec 22, 2022
) Towards elastic#147379 ## Summary When investigating how to [onboard detection alerts onto framework alert summaries](elastic#147379), there were some discrepancies in the format of the alert documents returned. This PR fixes the formatting so it matches and there will be no difference in `context.alerts` when we migrate detection alerts to the framework. ### Checklist - [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios
POC for onboarding detection rules: #147539 The framework will implement these issues in preparation for feature delivery: |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Feature:Alerting/RulesFramework
Issues related to the Alerting Rules Framework
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
In this effort, we should support the security solution to report their alerts 1:1 to the platform by leveraging the alert summaries feature. This will lay the groundwork necessary to develop future features like conditional actions where the alert actions may be per alert, a summarization or a group by of a different field.
The text was updated successfully, but these errors were encountered: