Skip to content

[DE][9.4 & Serverless] New space id filter available in Kibana advanced settings for all detection rules #5539

Merged
nastasha-solomon merged 11 commits into
mainfrom
docs-5270-detection-namespace-filter
Apr 9, 2026
Merged

[DE][9.4 & Serverless] New space id filter available in Kibana advanced settings for all detection rules #5539
nastasha-solomon merged 11 commits into
mainfrom
docs-5270-detection-namespace-filter

Conversation

@nastasha-solomon
Copy link
Copy Markdown
Member

@nastasha-solomon nastasha-solomon commented Mar 17, 2026

Summary

Fixes #5270.

  • Added docs for the securitySolution:includedDataStreamNamespacesForRuleExecution advanced setting.
  • Added a new troubleshooting subsection for missing/unexpected alerts if users suspect the namespace filter was excluding alerts.

Corresponding Kibana docs being added via elastic/kibana#261428.

Previews

Generative AI disclosure

  1. Did you use a generative AI (GenAI) tool to assist in creating this contribution?
  • Yes
  • No

Cursor + Claude

@nastasha-solomon nastasha-solomon self-assigned this Mar 17, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Mar 17, 2026

Vale Linting Results

Summary: 2 suggestions found

💡 Suggestions (2)
File Line Rule Message
troubleshoot/security/detection-rules.md 201 Elastic.Wordiness Consider using 'also' instead of 'In addition'.
troubleshoot/security/detection-rules.md 233 Elastic.Wordiness Consider using 'because' instead of 'since'.

The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Mar 17, 2026

@nastasha-solomon nastasha-solomon marked this pull request as ready for review March 20, 2026 20:22
@nastasha-solomon nastasha-solomon requested review from a team as code owners March 20, 2026 20:22
@florent-leborgne
Copy link
Copy Markdown
Member

florent-leborgne commented Mar 30, 2026

If there's a new advanced setting it should also go there https://github.com/elastic/kibana/blob/main/docs/reference/advanced-settings.md

Copy link
Copy Markdown
Member

@florent-leborgne florent-leborgne left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - see my note about also adding it to the kibana advanced settings reference

Comment thread troubleshoot/security/detection-rules.md Outdated
Comment thread troubleshoot/security/detection-rules.md Outdated
Copy link
Copy Markdown
Contributor

@dhurley14 dhurley14 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One clarification otherwise looks good 👍

Comment thread troubleshoot/security/detection-rules.md
Copy link
Copy Markdown
Contributor

@dhurley14 dhurley14 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approving ahead of changes

@nastasha-solomon nastasha-solomon merged commit 9b5f3dc into main Apr 9, 2026
7 checks passed
@nastasha-solomon nastasha-solomon deleted the docs-5270-detection-namespace-filter branch April 9, 2026 20:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Request] [Detections] New space id filter available in Kibana advanced settings for all detection rules

3 participants