[Security Solution] [Prebuilt Rules Customization] Add "Last Updated" column in the Add Elastic Rules and Rule Updates tables #174767
Labels
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Team:Detection Rule Management
Security Detection Rule Management Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
EPIC: #174168
Depends on:
source_updated_at
to Rule Schema as a Build Time Field detection-rules#2826source_updated_at
field toRuleResponse
viaResponseFields
#174740Describe the feature:
In our Add Elastic Rules and Rule Updates table, we want to show users a column with information of when was the rule last updated. This information will be provided in the prebuilt rule asset object and returned in the
RuleResponse
objects of our endpoints:POST /prebuilt_rules/installation/_review
andPOST /prebuilt_rules/upgrade/_review
.The user should be able to sort the table by this column, in order to see, which are the lastest updates, or in the opposite order, the updates which have been pending the most, i.e. more urgent.
*Designs:
Link: https://www.figma.com/file/gLHm8LpTtSkAUQHrkG3RHU/%5B8.7%5D-%5BRules%5D-Rule-Immutability%2FCustomization?type=design&node-id=2832-551423&mode=design&t=YgkGXlOjlZ9G0wWZ-0
Installation (Add Elastic Rules):
Upgrade (Rule Upgrades):
The text was updated successfully, but these errors were encountered: