[8.16] Updates docs for and related to the excludedDataTiersForRuleExecution advanced setting#5962
Conversation
|
A documentation preview will be available soon. Request a new doc build by commenting
If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here. |
excludedDataTiersForRuleExecution advanced setting
marshallmain
left a comment
There was a problem hiding this comment.
With the phrase The best path forward continues to be modifying the index patterns to only use hot tier data., are we specifically intending to reference guidance that we've provided before? An alternative might be The best path forward is to modify the index patterns to only use hot tier data..
Also @yctercero do we have a specific modification we can provide that works across the board, e.g. -partial* to exclude frozen indices? Do we know if that would work everywhere? Users might read "just modify your index patterns" and think that's a monumental task unless we have an easy specific change they can make.
Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com>
Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com>
benironside
left a comment
There was a problem hiding this comment.
Left a few minor comments which may or may not be helpful! Lmk when you're ready for an approval
…idoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
…idoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
…idoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com>
…xecution` advanced setting (#5962) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b)
…xecution` advanced setting (#5962) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b)
…orRuleExecution` advanced setting (backport #5962) (#6174) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
…rRuleExecution` advanced setting (backport #5962) (#6173) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
…orRuleExecution` advanced setting (backport #5962) (#6174) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit e6d6ec9) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
Fixes #5925 and https://github.com/elastic/security-docs-internal/issues/47 by updating the explanation for filtering out cold and frozen documents during rule executions and adding the disclaimer about certain rule types and cold/frozen shards.
Previews:
excludedDataTiersForRuleExecutionadvanced setting