Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RAC][Rule Registry] Cache rule data writers and index bootstrapping #110945

Closed
Tracked by #101016
banderror opened this issue Sep 2, 2021 · 4 comments
Closed
Tracked by #101016

[RAC][Rule Registry] Cache rule data writers and index bootstrapping #110945

banderror opened this issue Sep 2, 2021 · 4 comments
Labels
Team:Detection Alerts Security Detection Alerts Area Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: rac label obsolete

Comments

@banderror
Copy link
Contributor

Parent ticket: #101016
Depends on: #108941

Summary

When we move certain parts of the index bootstrapping logic to IRuleDataClient.getWriter() (#108941 (comment)) this method call will become relatively expensive.

We could implement caching for writers, so that when a user has a lot of detection rules in a Kibana space, it doesn't end up with thousands of requests to Elasticsearch in order to bootstrap resources for the same .alerts-security.alerts-{kibana-space-id} index. It shouldn't cache them forever, because in theory Kibana instances can run for a very long time. A short TTL might work.

@banderror banderror added Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: rac label obsolete labels Sep 2, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@banderror
Copy link
Contributor Author

Hey everyone, FYI ownership of this ticket and other tickets related to rule_registry (like #101016) now goes to the Detection Alerts area (Team:Detection Alerts label). Please ping @peluja1012 and @marshallmain if you have any questions.

@marshallmain
Copy link
Contributor

Completed in #113389

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:Detection Alerts Security Detection Alerts Area Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: rac label obsolete
Projects
None yet
Development

No branches or pull requests

3 participants