Skip to content

[RFC] Threat Enrichment - Stage 2#1460

Merged
ebeahan merged 5 commits intoelastic:masterfrom
rylnd:threat-enrichment-stage-2
Jun 24, 2021
Merged

[RFC] Threat Enrichment - Stage 2#1460
ebeahan merged 5 commits intoelastic:masterfrom
rylnd:threat-enrichment-stage-2

Conversation

@rylnd
Copy link
Copy Markdown
Contributor

@rylnd rylnd commented Jun 15, 2021

As follow up to #1400, this is the stage 2 RFC for threat enrichment. I believe that most of the stage 2 work has already been done, but I'm happy to be told otherwise.

RFC Preview

TODO

  • If submitting schema/fields updates, have you generated new artifacts by running make and committed those changes?
  • Have you added an entry to the CHANGELOG.next.md?

@rylnd rylnd added the RFC label Jun 15, 2021
@rylnd
Copy link
Copy Markdown
Contributor Author

rylnd commented Jun 15, 2021

@ebeahan my first question for stage 2 is: should this PR promote the declared fields so that they are included as beta fields, or is that done once this is merged (a la #1438) ?

@ebeahan
Copy link
Copy Markdown
Member

ebeahan commented Jun 16, 2021

@rylnd We've found separating the RFC PR from the implementation PR is cleaner, and it lets us focus more on the content and details of the proposal vs. clogging up the RFC discussion with potential ECS build issues, testing, tooling challenges, etc.

Copy link
Copy Markdown

@devonakerr devonakerr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor updates reflecting the stage advancement of this RFC look good to me.

Copy link
Copy Markdown
Member

@ebeahan ebeahan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

Review Criteria for Stage 2

  • Opened pull request for this draft revising the existing proposal
  • Completed field definitions
  • Included a real world example source document
  • Identifies scope of impact of changes to ingestion mechanisms (e.g. beats/logstash), usage mechanisms (e.g. Kibana applications, detections), and the ECS project (e.g. docs, tooling)
  • Subject matter experts weighed in on technical utility of field definitions in the pull request

@ebeahan ebeahan merged commit 04c4c9c into elastic:master Jun 24, 2021
@rylnd rylnd deleted the threat-enrichment-stage-2 branch June 24, 2021 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants