-
Notifications
You must be signed in to change notification settings - Fork 526
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Content] Add tag to rules with Investigation Guides #2297
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM,
Can you create an issue to add a test for this. It will be a bit more complicated than simply checking for rule.content.data.note
due to many only including a ## Setup
@brokensound77 I think we can maintain this as manual work, as some rules contain "incomplete" investigation guides that weren't reviewed by the docs team or don't fully follow the format. |
(cherry picked from commit ec04a39)
(cherry picked from commit ec04a39)
(cherry picked from commit ec04a39)
Issues
Part of https://github.com/elastic/security-team/issues/4378
Summary
Add the
has_guide
tag to rules with Investigation Guides so they can be easily identied on the stack.