Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create rule from timeline #2951

Closed
2 tasks done
nastasha-solomon opened this issue Jan 27, 2023 · 0 comments · Fixed by #3023
Closed
2 tasks done

Create rule from timeline #2951

nastasha-solomon opened this issue Jan 27, 2023 · 0 comments · Fixed by #3023
Assignees
Labels
Team: Threat Hunting Formerly Data Visibility v8.7.0

Comments

@nastasha-solomon
Copy link
Contributor

nastasha-solomon commented Jan 27, 2023

Description

Two new options (Create query rule from timeline and Create EQL rule from timeline) that allow users to create a rule from Timeline are being added to the overflow menu in the Timelines table. Users will have the option to create a query or EQL rule from a custom Timeline or from a Timeline template.

Related:

Required doc updates

Notes

  • Will be available by default (GA) in 8.7.
  • If Timeline has a custom query and an EQL query, both options appear in the overflow menu.
  • @stephmilovic is checking out possible bug that prevents users from creating a rule from a Timeline template. Issue/PR incoming.

To-do

  • Verify what the final copy for these options are. In 8.7.0 BC3, the option for creating a query rule is Create rule from timeline. In siem.dev, the copy is Create query rule from timeline.
  • Check whether there will also be an option to create a rule from within the Timeline view. - there is none
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: Threat Hunting Formerly Data Visibility v8.7.0
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant