You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two new options (Create query rule from timeline and Create EQL rule from timeline) that allow users to create a rule from Timeline are being added to the overflow menu in the Timelines table. Users will have the option to create a query or EQL rule from a custom Timeline or from a Timeline template.
If Timeline has a custom query and an EQL query, both options appear in the overflow menu.
@stephmilovic is checking out possible bug that prevents users from creating a rule from a Timeline template. Issue/PR incoming.
To-do
Verify what the final copy for these options are. In 8.7.0 BC3, the option for creating a query rule is Create rule from timeline. In siem.dev, the copy is Create query rule from timeline.
Check whether there will also be an option to create a rule from within the Timeline view. - there is none
The text was updated successfully, but these errors were encountered:
Description
Two new options (Create query rule from timeline and Create EQL rule from timeline) that allow users to create a rule from Timeline are being added to the overflow menu in the Timelines table. Users will have the option to create a query or EQL rule from a custom Timeline or from a Timeline template.
Related:
Required doc updates
Notes
To-do
8.7.0 BC3
, the option for creating a query rule is Create rule from timeline. In siem.dev, the copy is Create query rule from timeline.The text was updated successfully, but these errors were encountered: