Skip to content

[7.12] [DOCS] Updates Create Rule API docs for Threshold and Indicator Match Rules (#522)#540

Merged
spong merged 1 commit intoelastic:7.12from
spong:backport/7.12/pr-522
Mar 9, 2021
Merged

[7.12] [DOCS] Updates Create Rule API docs for Threshold and Indicator Match Rules (#522)#540
spong merged 1 commit intoelastic:7.12from
spong:backport/7.12/pr-522

Conversation

@spong
Copy link
Member

@spong spong commented Mar 9, 2021

Backports the following commits to 7.12:

… Rules (elastic#522)

This is a rough pass at updating the [Create Rule API docs](https://www.elastic.co/guide/en/security/current/rules-api-create.html#_request_body) for the recent changes surrounding `Threshold` and `Indicator Match` rules. @madirey and @rylnd if you could verify these changes and if any additional fields should be documented that would be greatly appreciated. 🙂 

Resolves: elastic/kibana#91965

Note: The grouping of optional fields per rule type makes these docs difficult to maintain (for me at least 😅), as you need to cross reference each optional field from each type, plus I'd bargain our users might find it useful to be able to look at all fields per each rule type independently. Something to verify with users/discuss, but would be a nice add for maintaining these docs (outside of writing scripts to generate the groupings).


##### Threshold Rules:
For more details on `cardinality_field` and `cardinality_value` see: elastic/kibana#90826


##### Indicator Match Rules:

For more details on `threat_filters` see: elastic/kibana#91260
@spong spong added the backport label Mar 9, 2021
@spong spong merged commit a302dd7 into elastic:7.12 Mar 9, 2021
@spong spong deleted the backport/7.12/pr-522 branch March 9, 2021 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant