Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SIEM][detection engine] Limit network rules to filebeat source semantics #57130

Merged
merged 2 commits into from
Feb 7, 2020
Merged

[SIEM][detection engine] Limit network rules to filebeat source semantics #57130

merged 2 commits into from
Feb 7, 2020

Conversation

dcode
Copy link
Contributor

@dcode dcode commented Feb 7, 2020

Summary

Removes non-filebeat indices from network detection rules in the siem.

Checklist

Delete any items that are not applicable to this PR.

For maintainers

Fixes elastic/mechagodzilla#99

@dcode dcode self-assigned this Feb 7, 2020
@dcode dcode added release_note:skip Skip the PR/issue when compiling release notes v7.6.0 v7.6.1 v7.7.0 v8.0.0 labels Feb 7, 2020
@dcode dcode changed the title limit network rules to filebeat source semantics [SIEM][detection engine] Limit network rules to filebeat source semantics Feb 7, 2020
@dcode dcode added the Team:SIEM label Feb 7, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

Copy link
Contributor

@FrankHassanabad FrankHassanabad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Contributor

@randomuserid randomuserid left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, please re-test on siem-dev to verify unit tests. I will add a paragraph about using these in the tuning guide docs.

@kibanamachine
Copy link
Contributor

💚 Build Succeeded

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@dcode dcode merged commit 1246a98 into elastic:master Feb 7, 2020
dcode added a commit to dcode/kibana that referenced this pull request Feb 8, 2020
…tics (elastic#57130)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
dcode added a commit to dcode/kibana that referenced this pull request Feb 8, 2020
…tics (elastic#57130)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
FrankHassanabad pushed a commit that referenced this pull request Feb 8, 2020
…tics (#57130) (#57161)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
FrankHassanabad pushed a commit that referenced this pull request Feb 8, 2020
…tics (#57130) (#57162)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
gmmorris added a commit to gmmorris/kibana that referenced this pull request Feb 9, 2020
…t-state

* upstream/master: (96 commits)
  top nav ts arg support (elastic#56984)
  [SIEM][detection engine] Limit network rules to filebeat source semantics (elastic#57130)
  Add docs for alerting and action settings (elastic#57035)
  Add Test to Verify Endpoint App Landing Page (elastic#57129)
  Update `markdown-to-jsx` (`6.9.3` → `6.11.0`) and `url-parse` (`1.4.4` → `1.4.7`) dependencies. (elastic#57126)
  chore(NA): removes use of parallel option in the terser minimizer (elastic#57077)
  [ML] New Platform server shim: update file data visualizer routes to use new platform router (elastic#56972)
  Specifying valid licenses for the Graph feature (elastic#55911)
  [APM][docs] Add troubleshooting for non-indexed fields (elastic#54948)
  [ML] DF Analytics creation: update schema definition for create route (elastic#56979)
  Remove Kibana a11y guide in favor of EUI (elastic#57021)
  [Logs UI] Set streamLive false in URL state when arriving from link-to (elastic#56329)
  [docs] Fix spaces api example json (elastic#50411)
  Add new config for filebeat index name (elastic#56920)
  [Metrics-UI] Fix toolbar popover for metrics table row (elastic#56796)
  Saved Objects testing (elastic#56965)
  Disabled categorization stats validation (elastic#57087)
  [Rollups] Server NP migration (elastic#55606)
  [Metrics UI] Limit group by selector to only 2 fields (elastic#56800)
  fix auto closing new vis modal when navigating to lens or when navigating away with browser history (elastic#56998)
  ...
gmmorris added a commit to gmmorris/kibana that referenced this pull request Feb 9, 2020
* master: (96 commits)
  top nav ts arg support (elastic#56984)
  [SIEM][detection engine] Limit network rules to filebeat source semantics (elastic#57130)
  Add docs for alerting and action settings (elastic#57035)
  Add Test to Verify Endpoint App Landing Page (elastic#57129)
  Update `markdown-to-jsx` (`6.9.3` → `6.11.0`) and `url-parse` (`1.4.4` → `1.4.7`) dependencies. (elastic#57126)
  chore(NA): removes use of parallel option in the terser minimizer (elastic#57077)
  [ML] New Platform server shim: update file data visualizer routes to use new platform router (elastic#56972)
  Specifying valid licenses for the Graph feature (elastic#55911)
  [APM][docs] Add troubleshooting for non-indexed fields (elastic#54948)
  [ML] DF Analytics creation: update schema definition for create route (elastic#56979)
  Remove Kibana a11y guide in favor of EUI (elastic#57021)
  [Logs UI] Set streamLive false in URL state when arriving from link-to (elastic#56329)
  [docs] Fix spaces api example json (elastic#50411)
  Add new config for filebeat index name (elastic#56920)
  [Metrics-UI] Fix toolbar popover for metrics table row (elastic#56796)
  Saved Objects testing (elastic#56965)
  Disabled categorization stats validation (elastic#57087)
  [Rollups] Server NP migration (elastic#55606)
  [Metrics UI] Limit group by selector to only 2 fields (elastic#56800)
  fix auto closing new vis modal when navigating to lens or when navigating away with browser history (elastic#56998)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release_note:skip Skip the PR/issue when compiling release notes Team:SIEM v7.6.1 v7.7.0 v8.0.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants