Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add rule docs for 8.6 rule changes #2751

Closed
wants to merge 1 commit into from

Conversation

terrancedejesus
Copy link
Contributor

Kibana Security Doc updates for rule changes in 8.6.

@terrancedejesus terrancedejesus added Team: Detections/Response Detections and Response Feature: Prebuilt rules trade-artifacts Issues related to TRADE artifact building and releasing v8.6.0 labels Nov 29, 2022
@terrancedejesus terrancedejesus self-assigned this Nov 29, 2022
@github-actions
Copy link

Documentation previews:

@@ -1,3 +1,6 @@
.DS_Store
docs/html_docs
/html_docs

# development files
*launch.json*
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added this to ignore debugging file for Python.

@@ -5,6 +5,9 @@ The following lists prebuilt rule updates per release. Only rules with
significant modifications to their query or scope are listed. For detailed
information about a rule's changes, see the rule's description page.

[float]
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should list all the files that have been changed, but does not. I will need to look into this.

@@ -15,7 +15,7 @@
PREBUILT_RULES = ROOT.joinpath('prebuilt-rules-scripts')
GENERATED_ASCII = ROOT.joinpath('generated-ascii-files')
DEFAULT_KIBANA_RULES_DIR = str(Path().joinpath('x-pack', 'plugins', 'security_solution', 'server', 'lib',
'detection_engine', 'rules', 'prepackaged_rules'))
'detection_engine', 'prebuilt_rules', 'content', 'prepackaged_rules'))
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated this so it points to the Kibana FS rules after recent change.

Reference - elastic/kibana#142950

@terrancedejesus
Copy link
Contributor Author

terrancedejesus commented Nov 29, 2022

These security docs do not seem to be correct as a result of a failed backport in Kibana. Since our process requires us to checkout Kibana branch 8.6 and then create docs from there, changes not backported would not be reflected in doc updates.

Reference - elastic/kibana#146402 (comment)

Update

Fixes were made so the rule changes successfully backported to the 8.6 branch of Kibana and as a result, building security docs will now reflect the expected rules. For 8.6.0 rule doc updates for Kibana, please refer to the following PR which has the correct diff.

@terrancedejesus terrancedejesus deleted the rule-updates-for-8.6.0 branch September 18, 2023 22:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature: Prebuilt rules Team: Detections/Response Detections and Response trade-artifacts Issues related to TRADE artifact building and releasing v8.6.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant