[RAC][Rule Registry] Implement separate methods for writing new alerts and updating existing ones #111175
Labels
Team:Detection Alerts
Security Detection Alerts Area Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Theme: rac
label obsolete
Parent ticket: #101016
Summary
Background: #110519 (comment)
The new methods should have simple and safe to use APIs which would keep developers away from making mistakes (related to providing concrete index names vs aliases, certain ES options etc).
The text was updated successfully, but these errors were encountered: