Skip to content

[9.0] [Security Solution] [Detection Engine] Logs shard failures for eql event queries on rule details page and in event log (#207396)#213616

Merged
marshallmain merged 1 commit intoelastic:9.0from
marshallmain:backport/9.0/pr-207396
Mar 7, 2025
Merged

Conversation

@marshallmain
Copy link
Contributor

…ent queries on rule details page and in event log (elastic#207396)

## Summary

Related: elastic/elasticsearch#116388

Adds support for shard failures for EQL event queries in the detection
engine.

(cherry picked from commit 4419390)
Copy link
Contributor

@dhurley14 dhurley14 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@marshallmain marshallmain merged commit 9d2649f into elastic:9.0 Mar 7, 2025
12 checks passed
@elasticmachine
Copy link
Contributor

💛 Build succeeded, but was flaky

Failed CI Steps

Test Failures

  • [job] [logs] FTR Configs #21 / EQL execution logic API @ess @serverless @serverlessQA EQL type rules parses shard failures for EQL event query

Metrics [docs]

✅ unchanged

@marshallmain marshallmain deleted the backport/9.0/pr-207396 branch April 4, 2025 19:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants