Skip to content

[SIEM][detection engine] Limit network rules to filebeat source semantics#57130

Merged
dcode merged 2 commits intoelastic:masterfrom
dcode:dcode/limit-network-rules-to-filebeat
Feb 7, 2020
Merged

[SIEM][detection engine] Limit network rules to filebeat source semantics#57130
dcode merged 2 commits intoelastic:masterfrom
dcode:dcode/limit-network-rules-to-filebeat

Conversation

@dcode
Copy link
Contributor

@dcode dcode commented Feb 7, 2020

Summary

Removes non-filebeat indices from network detection rules in the siem.

Checklist

Delete any items that are not applicable to this PR.

For maintainers

Fixes elastic/mechagodzilla#99

@dcode dcode self-assigned this Feb 7, 2020
@dcode dcode added release_note:skip Skip the PR/issue when compiling release notes v7.6.0 v7.6.1 v7.7.0 v8.0.0 labels Feb 7, 2020
@dcode dcode changed the title limit network rules to filebeat source semantics [SIEM][detection engine] Limit network rules to filebeat source semantics Feb 7, 2020
@dcode dcode added the Team:SIEM label Feb 7, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

Copy link
Contributor

@FrankHassanabad FrankHassanabad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Contributor

@randomuserid randomuserid left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, please re-test on siem-dev to verify unit tests. I will add a paragraph about using these in the tuning guide docs.

@kibanamachine
Copy link
Contributor

💚 Build Succeeded

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@dcode dcode merged commit 1246a98 into elastic:master Feb 7, 2020
dcode added a commit to dcode/kibana that referenced this pull request Feb 8, 2020
…tics (elastic#57130)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
dcode added a commit to dcode/kibana that referenced this pull request Feb 8, 2020
…tics (elastic#57130)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
FrankHassanabad pushed a commit that referenced this pull request Feb 8, 2020
…tics (#57130) (#57161)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
FrankHassanabad pushed a commit that referenced this pull request Feb 8, 2020
…tics (#57130) (#57162)

* limit network rules to filebeat source semantics

* Bump version number for network rules to ensure updates in post 7.6.0
gmmorris added a commit to gmmorris/kibana that referenced this pull request Feb 9, 2020
…t-state

* upstream/master: (96 commits)
  top nav ts arg support (elastic#56984)
  [SIEM][detection engine] Limit network rules to filebeat source semantics (elastic#57130)
  Add docs for alerting and action settings (elastic#57035)
  Add Test to Verify Endpoint App Landing Page (elastic#57129)
  Update `markdown-to-jsx` (`6.9.3` → `6.11.0`) and `url-parse` (`1.4.4` → `1.4.7`) dependencies. (elastic#57126)
  chore(NA): removes use of parallel option in the terser minimizer (elastic#57077)
  [ML] New Platform server shim: update file data visualizer routes to use new platform router (elastic#56972)
  Specifying valid licenses for the Graph feature (elastic#55911)
  [APM][docs] Add troubleshooting for non-indexed fields (elastic#54948)
  [ML] DF Analytics creation: update schema definition for create route (elastic#56979)
  Remove Kibana a11y guide in favor of EUI (elastic#57021)
  [Logs UI] Set streamLive false in URL state when arriving from link-to (elastic#56329)
  [docs] Fix spaces api example json (elastic#50411)
  Add new config for filebeat index name (elastic#56920)
  [Metrics-UI] Fix toolbar popover for metrics table row (elastic#56796)
  Saved Objects testing (elastic#56965)
  Disabled categorization stats validation (elastic#57087)
  [Rollups] Server NP migration (elastic#55606)
  [Metrics UI] Limit group by selector to only 2 fields (elastic#56800)
  fix auto closing new vis modal when navigating to lens or when navigating away with browser history (elastic#56998)
  ...
gmmorris added a commit to gmmorris/kibana that referenced this pull request Feb 9, 2020
* master: (96 commits)
  top nav ts arg support (elastic#56984)
  [SIEM][detection engine] Limit network rules to filebeat source semantics (elastic#57130)
  Add docs for alerting and action settings (elastic#57035)
  Add Test to Verify Endpoint App Landing Page (elastic#57129)
  Update `markdown-to-jsx` (`6.9.3` → `6.11.0`) and `url-parse` (`1.4.4` → `1.4.7`) dependencies. (elastic#57126)
  chore(NA): removes use of parallel option in the terser minimizer (elastic#57077)
  [ML] New Platform server shim: update file data visualizer routes to use new platform router (elastic#56972)
  Specifying valid licenses for the Graph feature (elastic#55911)
  [APM][docs] Add troubleshooting for non-indexed fields (elastic#54948)
  [ML] DF Analytics creation: update schema definition for create route (elastic#56979)
  Remove Kibana a11y guide in favor of EUI (elastic#57021)
  [Logs UI] Set streamLive false in URL state when arriving from link-to (elastic#56329)
  [docs] Fix spaces api example json (elastic#50411)
  Add new config for filebeat index name (elastic#56920)
  [Metrics-UI] Fix toolbar popover for metrics table row (elastic#56796)
  Saved Objects testing (elastic#56965)
  Disabled categorization stats validation (elastic#57087)
  [Rollups] Server NP migration (elastic#55606)
  [Metrics UI] Limit group by selector to only 2 fields (elastic#56800)
  fix auto closing new vis modal when navigating to lens or when navigating away with browser history (elastic#56998)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release_note:skip Skip the PR/issue when compiling release notes Team:SIEM v7.6.1 v7.7.0 v8.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants