Skip to content

[SIEM] Uses a dedicated index for job creation instead of the shared anomaly index#42297

Merged
FrankHassanabad merged 2 commits intoelastic:masterfrom
FrankHassanabad:use-dedicated-index-for-job-creation
Jul 30, 2019
Merged

[SIEM] Uses a dedicated index for job creation instead of the shared anomaly index#42297
FrankHassanabad merged 2 commits intoelastic:masterfrom
FrankHassanabad:use-dedicated-index-for-job-creation

Conversation

@FrankHassanabad
Copy link
Contributor

@FrankHassanabad FrankHassanabad commented Jul 30, 2019

Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only .ml-anomalies-shared but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward.

For testing:

  • Delete any existing jobs from your server and any test data in the ML UI:
  • Go to dev tools and run: GET /_cat/indices/.ml-anomalies-custom-*?v and verify you do not have any custom indexes prefixed with an existing SIEM job
  • Click the "Anomaly Button" in the SIEM application to re-install the jobs
  • Go to dev tools and run: GET /_cat/indices/.ml-*?v

Expectations are that you will see these indexes created:

health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb

- [ ] This was checked for cross-browser compatibility, including a check against IE11

- [ ] Documentation was added for features that require explanation or tutorials

- [ ] Unit or functional tests were updated or added to match the most common scenarios

- [ ] This was checked for keyboard-only and screenreader accessibility

For maintainers

- [ ] This was checked for breaking API changes and was labeled appropriately

Copy link
Member

@spong spong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked out, tested locally, and verified the following:

  • Both setup API calls /api/ml/modules/setup/siem_auditbeat_ecs & /api/ml/modules/setup/siem_winlogbeat_ecs now include useDedicatedIndex: true in the request payload
  • That the dedicated indices exist after job creation:
green open .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs ru8vhC_bT3Smf2b-G0eYfQ 1 0 0 0 230b 230b
green open .ml-anomalies-custom-siem-api-rare_process_windows_ecs      zDYUqYSiSVaNValzvsp-LQ 1 0 0 0 230b 230b
green open .ml-anomalies-custom-siem-api-rare_process_linux_ecs        5jVD96kWTymOl1Ye8EiKbw 1 0 0 0 230b 230b
  • That the ml-anomalies-shared is no longer polluted with additional fields from the above jobs

LGTM! 👍

@elasticmachine
Copy link
Contributor

💚 Build Succeeded

@FrankHassanabad FrankHassanabad merged commit db70daa into elastic:master Jul 30, 2019
@FrankHassanabad FrankHassanabad deleted the use-dedicated-index-for-job-creation branch July 30, 2019 22:34
FrankHassanabad added a commit to FrankHassanabad/kibana that referenced this pull request Jul 30, 2019
## Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

### Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only `.ml-anomalies-shared` but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward. 

For testing:

* Delete any existing jobs from your server and any test data in the ML UI:
* Go to dev tools and run: `GET /_cat/indices/.ml-anomalies-custom-*?v` and verify you do not have any custom indexes prefixed with an existing SIEM job 
* Click the "Anomaly Button" in the SIEM application to re-install the jobs
* Go to dev tools and run: `GET /_cat/indices/.ml-*?v`

Expectations are that you will see these indexes created:

```ts
health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb
```

~~- [ ] This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~~

- [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)

~~- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials~~

~~- [ ] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~~

~~- [ ] This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~~

### For maintainers

~~- [ ] This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~~

- [x] This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)
FrankHassanabad added a commit that referenced this pull request Jul 31, 2019
## Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

### Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only `.ml-anomalies-shared` but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward. 

For testing:

* Delete any existing jobs from your server and any test data in the ML UI:
* Go to dev tools and run: `GET /_cat/indices/.ml-anomalies-custom-*?v` and verify you do not have any custom indexes prefixed with an existing SIEM job 
* Click the "Anomaly Button" in the SIEM application to re-install the jobs
* Go to dev tools and run: `GET /_cat/indices/.ml-*?v`

Expectations are that you will see these indexes created:

```ts
health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb
```

~~- [ ] This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~~

- [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)

~~- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials~~

~~- [ ] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~~

~~- [ ] This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~~

### For maintainers

~~- [ ] This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~~

- [x] This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)
jloleysens added a commit to jloleysens/kibana that referenced this pull request Jul 31, 2019
…-or-edit-existing-rollup-job

* 'master' of github.com:elastic/kibana: (114 commits)
  [ML] Fixing empty index pattern list (elastic#42299)
  [Markdown] Shim new platform - cleanup plugin (elastic#41760)
  [Code] Enable hierarchicalDocumentSymbolSupport for java language server (elastic#42233)
  Add New Platform mocks for data plugin (elastic#42261)
  Http server route handler implementation (elastic#41894)
  [SR] Allow custom index pattern to be used instead of selectable list when choosing indices to restore (elastic#41534)
  [Code] distributed Code abstraction (elastic#41374)
  [SIEM] Sets page titles to the current page you are on  (elastic#42157)
  Saved Objects export API stable type order (elastic#42310)
  cancellation of interpreter execution (elastic#40238)
  [SIEM] Fixes a crash when Machine Learning influencers is an undefined value (elastic#42198)
  Changed the job to work with a dedicated index (elastic#42297)
  FTR: fix testSubjects.missingOrFail (elastic#42290)
  Increase retry timeout to prevent flaky tests (elastic#42291)
  Spaces - make space a hidden saved object type (elastic#41688)
  Allow applications to register feature privileges which are excluded from the base privileges (elastic#41300)
  Disable flaky log column reorder test (elastic#42285)
  Fixing add element in element reducer (elastic#42276)
  Fix infinite loop (elastic#42228)
  [Maps][File upload] Remove geojson deep clone logic, handle on maps side (elastic#41835)
  ...
spong pushed a commit to spong/kibana that referenced this pull request Aug 1, 2019
## Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

### Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only `.ml-anomalies-shared` but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward. 

For testing:

* Delete any existing jobs from your server and any test data in the ML UI:
* Go to dev tools and run: `GET /_cat/indices/.ml-anomalies-custom-*?v` and verify you do not have any custom indexes prefixed with an existing SIEM job 
* Click the "Anomaly Button" in the SIEM application to re-install the jobs
* Go to dev tools and run: `GET /_cat/indices/.ml-*?v`

Expectations are that you will see these indexes created:

```ts
health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb
```

~~- [ ] This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~~

- [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)

~~- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials~~

~~- [ ] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~~

~~- [ ] This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~~

### For maintainers

~~- [ ] This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~~

- [x] This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)
spong added a commit that referenced this pull request Aug 2, 2019
## Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

### Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only `.ml-anomalies-shared` but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward. 

For testing:

* Delete any existing jobs from your server and any test data in the ML UI:
* Go to dev tools and run: `GET /_cat/indices/.ml-anomalies-custom-*?v` and verify you do not have any custom indexes prefixed with an existing SIEM job 
* Click the "Anomaly Button" in the SIEM application to re-install the jobs
* Go to dev tools and run: `GET /_cat/indices/.ml-*?v`

Expectations are that you will see these indexes created:

```ts
health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb
```

~~- [ ] This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~~

- [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)

~~- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials~~

~~- [ ] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~~

~~- [ ] This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~~

### For maintainers

~~- [ ] This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~~

- [x] This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants