Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ResponseOps] add saved object names to audit documents #178974

Closed
pmuellr opened this issue Mar 19, 2024 · 4 comments
Closed

[ResponseOps] add saved object names to audit documents #178974

pmuellr opened this issue Mar 19, 2024 · 4 comments
Labels
Feature:Actions Feature:Alerting Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)

Comments

@pmuellr
Copy link
Member

pmuellr commented Mar 19, 2024

enhancement request: https://github.com/elastic/enhancements/issues/19823

newly merged basic audit capability to store saved object names in audit documents: #175626

For alerting saved objects, we should start using the appropriate "name" of the object in our calls to the audit logger. This certainly means rules and connectors, not sure if other saved objects are applicable

@pmuellr pmuellr added Feature:Alerting Feature:Actions Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) labels Mar 19, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/response-ops (Team:ResponseOps)

@ymao1
Copy link
Contributor

ymao1 commented Mar 21, 2024

cc @XavierM Is this something the RAM team could handle?

@pmuellr pmuellr moved this from Awaiting Triage to Todo in AppEx: ResponseOps - Execution & Connectors Mar 28, 2024
@mbudge
Copy link

mbudge commented Apr 16, 2024

+1

Our IT security controls team are currently trying to build dashboards and reporting for SIEM security rules. A big improvement will be adding the security rule name to the dashboards and reporting.

@doakalexi
Copy link
Contributor

Going to close this issue, it looks like the Management Experience team is using the enhancement request issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Actions Feature:Alerting Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)
Projects
None yet
Development

No branches or pull requests

5 participants