-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[DOCS] Adds warning about exceptions requiring mappings #2110
Conversation
This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule.
Wording is subject to change; just throwing something at the wall for now.
Note: since this has always been the behavior of exceptions, it'd be nice to backport this note to previous docs versions as well. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for filing this @rylnd ! Just left one comment for your consideration. My last two comments are minor editorial nits and I directed them towards Joe since he'll have the answer for them.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, with @nastasha-solomon's edits
Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
@Mergifyio backport 7.9 |
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc
✅ Backports have been created
|
https://github.com/Mergifyio backport 7.10 7.11 7.12 7.13 |
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc
✅ Backports have been created
|
…ort #2110) (#2118) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Resolve merge conflicts with 7.17 branch. Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2120) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Resolve merge conflicts with 7.16 branch. Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2121) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Resolve merge conflicts with 7.15 branch. Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2122) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Resolve merge conflicts with 7.14 branch. Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2124) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Fix conflicts with 7.10 branch Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2125) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Fix conflicts on 7.11 branch Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2126) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Fix conflicts with 7.12 branch Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
…ort #2110) (#2127) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Fix conflicts with 7.13 branch Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
#2110) (#2123) * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit aeb69a6) # Conflicts: # docs/detections/detections-ui-exceptions.asciidoc * Fix conflicts with 7.9 branch * Adds back the new callout Conflicts ended up deleting this previously. Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
* First draft * Add placeholder for instructions for self-hosted * updates formatting * updates format and image size * Updates formatting and annotates screenshots * updates to the main intro and some terms here and there * [DOCS] Revise workaround for aggregated fields in threshold rules (#2074) * Remove workaround from create rule docs * Restore admonition, with revisions from Madison * [DOCS][8.3] Updates "Endpoint Security" to "Endpoint and Cloud Security" screenshots (#2075) * Updates screenshots and replaces the old name with the new name. * Updates text, fixes image names * Update docs/getting-started/install-endpoint.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/getting-started/install-endpoint.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Fix bugs found by QA Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Add example response section (#2084) * [DOCS] Add new EQL search configuration options (#2061) * Update eql-rule-query-example.png * Update procedure for creating EQL rule * Update API docs: create rule, update rule * Align minor phrasing * Explain timestamp_field & timestamp_override * Updates based on review feedback * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * [DOCS] Removed ref to Stack GS (#2128) * Minor edits to Tin's work * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Matches order of sections to order they're mentioned in the intro * Changes bullets to numbers * Update docs/experimental-features/experimental-features-intro.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/experimental-features-intro.asciidoc * Incorporate Joe's and Janeen's feedback * fixes build error * troubleshoots build error * troubleshoots build error * troubleshoots build erors Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Ryland Herrick <ryalnd@gmail.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: debadair <debadair@elastic.co> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
* First draft * Add placeholder for instructions for self-hosted * updates formatting * updates format and image size * Updates formatting and annotates screenshots * updates to the main intro and some terms here and there * [DOCS] Revise workaround for aggregated fields in threshold rules (#2074) * Remove workaround from create rule docs * Restore admonition, with revisions from Madison * [DOCS][8.3] Updates "Endpoint Security" to "Endpoint and Cloud Security" screenshots (#2075) * Updates screenshots and replaces the old name with the new name. * Updates text, fixes image names * Update docs/getting-started/install-endpoint.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/getting-started/install-endpoint.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Fix bugs found by QA Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Add example response section (#2084) * [DOCS] Add new EQL search configuration options (#2061) * Update eql-rule-query-example.png * Update procedure for creating EQL rule * Update API docs: create rule, update rule * Align minor phrasing * Explain timestamp_field & timestamp_override * Updates based on review feedback * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * [DOCS] Removed ref to Stack GS (#2128) * Minor edits to Tin's work * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Matches order of sections to order they're mentioned in the intro * Changes bullets to numbers * Update docs/experimental-features/experimental-features-intro.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/experimental-features-intro.asciidoc * Incorporate Joe's and Janeen's feedback * fixes build error * troubleshoots build error * troubleshoots build error * troubleshoots build erors Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Ryland Herrick <ryalnd@gmail.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: debadair <debadair@elastic.co> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> (cherry picked from commit edeecb9)
* First draft * Add placeholder for instructions for self-hosted * updates formatting * updates format and image size * Updates formatting and annotates screenshots * updates to the main intro and some terms here and there * [DOCS] Revise workaround for aggregated fields in threshold rules (#2074) * Remove workaround from create rule docs * Restore admonition, with revisions from Madison * [DOCS][8.3] Updates "Endpoint Security" to "Endpoint and Cloud Security" screenshots (#2075) * Updates screenshots and replaces the old name with the new name. * Updates text, fixes image names * Update docs/getting-started/install-endpoint.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/getting-started/install-endpoint.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Fix bugs found by QA Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Add example response section (#2084) * [DOCS] Add new EQL search configuration options (#2061) * Update eql-rule-query-example.png * Update procedure for creating EQL rule * Update API docs: create rule, update rule * Align minor phrasing * Explain timestamp_field & timestamp_override * Updates based on review feedback * [DOCS] Adds warning about exceptions requiring mappings (#2110) * Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * [DOCS] Removed ref to Stack GS (#2128) * Minor edits to Tin's work * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> * Matches order of sections to order they're mentioned in the intro * Changes bullets to numbers * Update docs/experimental-features/experimental-features-intro.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/security-posture-management.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/experimental-features/experimental-features-intro.asciidoc * Incorporate Joe's and Janeen's feedback * fixes build error * troubleshoots build error * troubleshoots build error * troubleshoots build erors Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Ryland Herrick <ryalnd@gmail.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: debadair <debadair@elastic.co> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> (cherry picked from commit edeecb9) Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
* Move callout about endpoint exceptions to more appropriate section This not was previously at the top-level exceptions section, when it really only applies when adding to the Endpoint rule. * Add note about mappings being required for exceptions Wording is subject to change; just throwing something at the wall for now. * Apply suggestions from code review Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
Preview of Exceptions page
This PR is meant to address elastic/kibana#133078 to a degree, by calling out that mappings are required for exceptions to function. While elastic/kibana#133078 is not a bug, it is an unexpected behavior (for which we've received some SDHs), and this note is an attempt to make that ... less unexpected.
I believe that the majority of the necessary info is here, but I'd appreciate a review of copy/syntax etc. Not sure if this fits docs' guidelines and/or is legible.