Skip to content

[7.3] [SIEM] Uses a dedicated index for job creation instead of the shared anomaly index(#42297)#42465

Merged
spong merged 1 commit intoelastic:7.3from
spong:backport/7.3/pr-42297
Aug 2, 2019
Merged

[7.3] [SIEM] Uses a dedicated index for job creation instead of the shared anomaly index(#42297)#42465
spong merged 1 commit intoelastic:7.3from
spong:backport/7.3/pr-42297

Conversation

@spong
Copy link
Member

@spong spong commented Aug 1, 2019

Backports the following commits to 7.3:

## Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

### Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only `.ml-anomalies-shared` but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward. 

For testing:

* Delete any existing jobs from your server and any test data in the ML UI:
* Go to dev tools and run: `GET /_cat/indices/.ml-anomalies-custom-*?v` and verify you do not have any custom indexes prefixed with an existing SIEM job 
* Click the "Anomaly Button" in the SIEM application to re-install the jobs
* Go to dev tools and run: `GET /_cat/indices/.ml-*?v`

Expectations are that you will see these indexes created:

```ts
health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb
```

~~- [ ] This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~~

- [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)

~~- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials~~

~~- [ ] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~~

~~- [ ] This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~~

### For maintainers

~~- [ ] This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~~

- [x] This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)
@spong spong added the backport This PR is a backport of another PR label Aug 1, 2019
@spong spong changed the title [7.3] Changed the job to work with a dedicated index (#42297) [7.3] [SIEM] Uses a dedicated index for job creation instead of the shared anomaly index(#42297) Aug 1, 2019
@spong
Copy link
Member Author

spong commented Aug 2, 2019

retest

@elasticmachine
Copy link
Contributor

💚 Build Succeeded

@spong spong merged commit db2d314 into elastic:7.3 Aug 2, 2019
@spong spong deleted the backport/7.3/pr-42297 branch August 2, 2019 13:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants