Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Content] Add tag to rules with Investigation Guides #2297

Merged
merged 2 commits into from
Sep 23, 2022
Merged

Conversation

w0rk3r
Copy link
Contributor

@w0rk3r w0rk3r commented Sep 13, 2022

Issues

Part of https://github.com/elastic/security-team/issues/4378

Summary

Add the has_guide tag to rules with Investigation Guides so they can be easily identied on the stack.

@w0rk3r w0rk3r self-assigned this Sep 13, 2022
@w0rk3r w0rk3r marked this pull request as ready for review September 13, 2022 19:02
Copy link
Contributor

@brokensound77 brokensound77 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM,

Can you create an issue to add a test for this. It will be a bit more complicated than simply checking for rule.content.data.note due to many only including a ## Setup

@w0rk3r
Copy link
Contributor Author

w0rk3r commented Sep 23, 2022

@brokensound77 I think we can maintain this as manual work, as some rules contain "incomplete" investigation guides that weren't reviewed by the docs team or don't fully follow the format.

@w0rk3r w0rk3r merged commit ec04a39 into main Sep 23, 2022
@w0rk3r w0rk3r deleted the ig_tagging branch September 23, 2022 17:20
protectionsmachine pushed a commit that referenced this pull request Sep 23, 2022
protectionsmachine pushed a commit that referenced this pull request Sep 23, 2022
protectionsmachine pushed a commit that referenced this pull request Sep 23, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants