Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Support exporting prebuilt rules from the Rule Details page #180176

Closed
2 tasks done
Tracked by #174168
jpdjere opened this issue Apr 5, 2024 · 4 comments · Fixed by #198202
Closed
2 tasks done
Tracked by #174168

[Security Solution] Support exporting prebuilt rules from the Rule Details page #180176

jpdjere opened this issue Apr 5, 2024 · 4 comments · Fixed by #198202
Assignees
Labels
8.17 candidate Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@jpdjere
Copy link
Contributor

jpdjere commented Apr 5, 2024

Epics: https://github.com/elastic/security-team/issues/1974 (internal), #174168

Summary

  • Support exporting prebuilt rules from the Rule Details page

Background

In the UI we have a logic gate to prevent showing the "export" button as enabled unless the rule.immutable is false. With the milestone 3 efforts, this restriction has been removed in the API behind the prebuiltRulesCustomizationEnabled feature flag and can now be removed in the UI behind the feature flag as well.

Acceptance criteria

  • User is able to export all rule types (including prebuilt rules) from Rule Details page
  • Feature is hidden behind feature flag
@jpdjere jpdjere added triage_needed Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area labels Apr 5, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-rule-management (Team:Detection Rule Management)

@banderror banderror changed the title [Security Solution] Support exporting prebuilt rules from the Rule Details page [Security Solution] Support exporting prebuilt rules from the Rule Details page (DRAFT) Apr 17, 2024
@nacio-foxy
Copy link

This would be very useful to review prebuilt rules in bulk through a csv (or something else) export and we could work collaboratively on them with the team for reviewing, assessing priority, etc..

@banderror banderror assigned dplumlee and unassigned rylnd Oct 9, 2024
@dplumlee dplumlee changed the title [Security Solution] Support exporting prebuilt rules from the Rule Details page (DRAFT) [Security Solution] Support exporting prebuilt rules from the Rule Details page Nov 4, 2024
kibanamachine pushed a commit to kibanamachine/kibana that referenced this issue Nov 13, 2024
…the Rule Management and Rule Details pages (elastic#198202)

**Resolves: elastic#180171
**Resolves: elastic#180176
**Resolves: elastic#180173

## Summary

> [!NOTE]
> Feature is behind the `prebuiltRulesCustomizationEnabled` feature
flag.

Adds logic to allow users to edit and export prebuilt rules from both
the Rule management page and Rule details page via the bulk action menu
and the singular overflow menu

### Acceptance criteria

- [x] Feature is hidden behind prebuiltRulesCustomizationEnabled feature
flag
- [x] Modified components still work as expected when feature flag is
off
- [x] Bulk actions are able to performed on all rule types from Rule
management page bulk actions menu
  - [x] Editing
    - [x] Index patterns
    - [x] Tags
    - [x] Highlighted fields
    - [x] Schedule
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule management page overflow column
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule details page
  - [x] Export

### Screenshots
***

### Rule management table overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 38
12 PM](https://github.com/user-attachments/assets/13f8cd87-a9e5-486c-ab0f-d206de8bab4b)

#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
27 PM](https://github.com/user-attachments/assets/4b3d9364-02d5-406a-9f8a-c9ad8fed8486)

### Rule details page overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 37
40 PM](https://github.com/user-attachments/assets/621b56e3-1f47-49db-aedb-fd05a3b75007)

#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
38 PM](https://github.com/user-attachments/assets/d533f288-4393-4acf-ba88-91c32ab32955)

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
(cherry picked from commit 02e4edc)
CAWilson94 pushed a commit to CAWilson94/kibana that referenced this issue Nov 18, 2024
…the Rule Management and Rule Details pages (elastic#198202)

**Resolves: elastic#180171
**Resolves: elastic#180176
**Resolves: elastic#180173

## Summary

> [!NOTE]  
> Feature is behind the `prebuiltRulesCustomizationEnabled` feature
flag.

Adds logic to allow users to edit and export prebuilt rules from both
the Rule management page and Rule details page via the bulk action menu
and the singular overflow menu


### Acceptance criteria

- [x] Feature is hidden behind prebuiltRulesCustomizationEnabled feature
flag
- [x] Modified components still work as expected when feature flag is
off
- [x] Bulk actions are able to performed on all rule types from Rule
management page bulk actions menu
  - [x] Editing
    - [x] Index patterns
    - [x] Tags
    - [x] Highlighted fields
    - [x] Schedule
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule management page overflow column
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule details page
  - [x] Export
 

### Screenshots
***

### Rule management table overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 38
12 PM](https://github.com/user-attachments/assets/13f8cd87-a9e5-486c-ab0f-d206de8bab4b)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
27 PM](https://github.com/user-attachments/assets/4b3d9364-02d5-406a-9f8a-c9ad8fed8486)

### Rule details page overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 37
40 PM](https://github.com/user-attachments/assets/621b56e3-1f47-49db-aedb-fd05a3b75007)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
38 PM](https://github.com/user-attachments/assets/d533f288-4393-4acf-ba88-91c32ab32955)

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
CAWilson94 pushed a commit to CAWilson94/kibana that referenced this issue Nov 18, 2024
…the Rule Management and Rule Details pages (elastic#198202)

**Resolves: elastic#180171
**Resolves: elastic#180176
**Resolves: elastic#180173

## Summary

> [!NOTE]  
> Feature is behind the `prebuiltRulesCustomizationEnabled` feature
flag.

Adds logic to allow users to edit and export prebuilt rules from both
the Rule management page and Rule details page via the bulk action menu
and the singular overflow menu


### Acceptance criteria

- [x] Feature is hidden behind prebuiltRulesCustomizationEnabled feature
flag
- [x] Modified components still work as expected when feature flag is
off
- [x] Bulk actions are able to performed on all rule types from Rule
management page bulk actions menu
  - [x] Editing
    - [x] Index patterns
    - [x] Tags
    - [x] Highlighted fields
    - [x] Schedule
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule management page overflow column
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule details page
  - [x] Export
 

### Screenshots
***

### Rule management table overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 38
12 PM](https://github.com/user-attachments/assets/13f8cd87-a9e5-486c-ab0f-d206de8bab4b)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
27 PM](https://github.com/user-attachments/assets/4b3d9364-02d5-406a-9f8a-c9ad8fed8486)

### Rule details page overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 37
40 PM](https://github.com/user-attachments/assets/621b56e3-1f47-49db-aedb-fd05a3b75007)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
38 PM](https://github.com/user-attachments/assets/d533f288-4393-4acf-ba88-91c32ab32955)

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
8.17 candidate Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
6 participants