Skip to content

[Detection Engine] Remove technical preview for certain rule types of alert suppression#195425

Merged
yctercero merged 9 commits intoelastic:mainfrom
yctercero:remove_tech_preview_suppression
Oct 10, 2024
Merged

[Detection Engine] Remove technical preview for certain rule types of alert suppression#195425
yctercero merged 9 commits intoelastic:mainfrom
yctercero:remove_tech_preview_suppression

Conversation

@yctercero
Copy link
Copy Markdown
Contributor

@yctercero yctercero commented Oct 8, 2024

Summary

GA-ing alert suppression for IM rule, ML rule, Threshold rule, ES|QL rule and New Terms rule. Thanks to @vitaliidm for setting up the groundwork to easily update which rules GA.

Rules that remain in technical preview are: EQL.

Screenshots below are the updated states.

Rule creation

EQL

Screenshot 2024-10-07 at 2 38 09 PM

Threshold

Screenshot 2024-10-07 at 2 41 17 PM

New terms

Screenshot 2024-10-07 at 2 38 24 PM

ES|QL

Screenshot 2024-10-07 at 2 38 34 PM

Indicator Match

Screenshot 2024-10-07 at 2 38 16 PM

Custom Query

Screenshot 2024-10-07 at 2 38 44 PM

ML

Screenshot 2024-10-09 at 1 17 26 PM
Rule details

EQL

Screenshot 2024-10-07 at 2 49 48 PM

ES|QL

Screenshot 2024-10-07 at 2 45 20 PM

Threshold

Screenshot 2024-10-07 at 2 44 18 PM

New Terms

Screenshot 2024-10-07 at 2 46 48 PM

IM

Screenshot 2024-10-07 at 2 49 11 PM

ML

Screenshot 2024-10-09 at 1 18 59 PM
Alert details

EQL

Screenshot 2024-10-08 at 7 19 59 AM

GA-ed rules

Screenshot 2024-10-08 at 7 20 15 AM

@yctercero yctercero requested review from a team as code owners October 8, 2024 14:21
@yctercero yctercero requested a review from nkhristinin October 8, 2024 14:21
@yctercero yctercero assigned yctercero and unassigned yctercero Oct 8, 2024
@yctercero yctercero added v9.0.0 v8.16.0 release_note:skip Skip the PR/issue when compiling release notes Team:Detection Engine Security Solution Detection Engine Area labels Oct 8, 2024
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/security-detection-engine (Team:Detection Engine)

@yctercero yctercero added the backport:version Backport to applied version labels label Oct 8, 2024
@yctercero yctercero requested a review from approksiu October 8, 2024 14:33
@approksiu
Copy link
Copy Markdown

Let's align on ML rule type, the rest is good!

@yctercero
Copy link
Copy Markdown
Contributor Author

Let's align on ML rule type, the rest is good!

Chatted with @rylnd and GA-ing ML suppression.

@elasticmachine
Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

Async chunks

Total size of all lazy-loaded chunks that will be downloaded as the user navigates the app

id before after diff
securitySolution 20.6MB 20.6MB -170.0B

Page load bundle

Size of the bundles that are downloaded on every page load. Target size is below 100kb

id before after diff
securitySolution 88.4KB 88.4KB +65.0B

History

cc @yctercero

@yctercero yctercero merged commit 65ed989 into elastic:main Oct 10, 2024
@kibanamachine
Copy link
Copy Markdown
Contributor

Starting backport for target branches: 8.x

https://github.com/elastic/kibana/actions/runs/11265043811

kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Oct 10, 2024
… alert suppression (elastic#195425)

## Summary

GA-ing alert suppression for IM rule, ML rule, Threshold rule, ES|QL
rule and New Terms rule. Thanks to @vitaliidm for setting up the
groundwork to easily update which rules GA.

Rules that remain in technical preview are: EQL.

(cherry picked from commit 65ed989)
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 All backports created successfully

Status Branch Result
8.x

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request Oct 10, 2024
…pes of alert suppression (#195425) (#195694)

# Backport

This will backport the following commits from `main` to `8.x`:
- [[Detection Engine] Remove technical preview for certain rule types of
alert suppression
(#195425)](#195425)

<!--- Backport version: 9.4.3 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sqren/backport)

<!--BACKPORT [{"author":{"name":"Yara
Tercero","email":"yctercero@users.noreply.github.com"},"sourceCommit":{"committedDate":"2024-10-10T00:14:03Z","message":"[Detection
Engine] Remove technical preview for certain rule types of alert
suppression (#195425)\n\n## Summary\r\n\r\nGA-ing alert suppression for
IM rule, ML rule, Threshold rule, ES|QL\r\nrule and New Terms rule.
Thanks to @vitaliidm for setting up the\r\ngroundwork to easily update
which rules GA.\r\n\r\nRules that remain in technical preview are:
EQL.","sha":"65ed9899de2733ec7017ef7277bd24723131684a","branchLabelMapping":{"^v9.0.0$":"main","^v8.16.0$":"8.x","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:skip","v9.0.0","Team:Detection
Engine","v8.16.0","backport:version"],"title":"[Detection Engine] Remove
technical preview for certain rule types of alert
suppression","number":195425,"url":"https://github.com/elastic/kibana/pull/195425","mergeCommit":{"message":"[Detection
Engine] Remove technical preview for certain rule types of alert
suppression (#195425)\n\n## Summary\r\n\r\nGA-ing alert suppression for
IM rule, ML rule, Threshold rule, ES|QL\r\nrule and New Terms rule.
Thanks to @vitaliidm for setting up the\r\ngroundwork to easily update
which rules GA.\r\n\r\nRules that remain in technical preview are:
EQL.","sha":"65ed9899de2733ec7017ef7277bd24723131684a"}},"sourceBranch":"main","suggestedTargetBranches":["8.x"],"targetPullRequestStates":[{"branch":"main","label":"v9.0.0","branchLabelMappingKey":"^v9.0.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/195425","number":195425,"mergeCommit":{"message":"[Detection
Engine] Remove technical preview for certain rule types of alert
suppression (#195425)\n\n## Summary\r\n\r\nGA-ing alert suppression for
IM rule, ML rule, Threshold rule, ES|QL\r\nrule and New Terms rule.
Thanks to @vitaliidm for setting up the\r\ngroundwork to easily update
which rules GA.\r\n\r\nRules that remain in technical preview are:
EQL.","sha":"65ed9899de2733ec7017ef7277bd24723131684a"}},{"branch":"8.x","label":"v8.16.0","branchLabelMappingKey":"^v8.16.0$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:version Backport to applied version labels release_note:skip Skip the PR/issue when compiling release notes Team:Detection Engine Security Solution Detection Engine Area v8.16.0 v9.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants