[Security Solution][Discuss] Categorization & Description of Detection Rules #77250
Labels
discuss
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Team:SIEM
In adding the new EQL Rule type, there was discussion about the distinctions between the Query type and the EQL type, and how we clarify those to the user. The goal of this issue is to clarify the behavior/use case of each rule type that we present to the user.
To quote from the aforementioned discussion:
As a more direct prompt, I would say there are two questions being asked here:
The text was updated successfully, but these errors were encountered: