Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] Advanced rule query preview option available #2227

Closed
Tracked by #2258
nastasha-solomon opened this issue Jul 27, 2022 · 1 comment
Closed
Tracked by #2258

[DOCS] Advanced rule query preview option available #2227

nastasha-solomon opened this issue Jul 27, 2022 · 1 comment

Comments

@nastasha-solomon
Copy link
Contributor

nastasha-solomon commented Jul 27, 2022

Description

In 8.3 and earlier, users could only choose three timeframes to preview rule results in: Last hour, Last day, or Last month. Users would select these options from the drop-down under the Quick query preview section and then click Preview results to generate a preview. Full steps are doc'd here.

old-preview-feature

In 8.4, users will be offered two preview options. The first and default option will be the Quick query preview, which is the "old" rule preview feature. The second will be the new Advanced query preview option. This new option gives users more control over the preview's timeframe, rule interval, and look-back time, providing them with an even more realistic representation of what they can expect to see after they enable the rule.

new-preview-feature

Related:

Notes

  • The default values for the three fields are:
    • Timeframe: Last 1 hour
    • Runs every (Rule interval): 5 Minutes
    • Additional look-back time: 1 Minutes
  • Some rules require certain fields to be set or filled out for the preview option to work:
    • ML: The select job must be running.
    • IM: Indicator mappings must be set.
    • New Terms: The Fields field must have a value.
  • Notes on default options and pre-reqs for rule preview to work: https://docs.google.com/spreadsheets/d/13Z9QtTCP6zO4NGWrdSBImL3xnh5ps3fCUHihI-LWb48/edit#gid=0
@nastasha-solomon nastasha-solomon self-assigned this Jul 27, 2022
@nastasha-solomon nastasha-solomon changed the title [DOCS] [DRAFT] Users can configure the time interval and look-back time for rule previews [DOCS] Advanced rule query preview option available Aug 3, 2022
@nastasha-solomon
Copy link
Contributor Author

Merged #2251.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants