Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Prebuilt Rule Links for Malicious Site in 7.14 #4272

Closed
wants to merge 250 commits into from

Conversation

terrancedejesus
Copy link
Contributor

narcher7 and others added 30 commits May 15, 2020 09:03
* dumnps siem stuff

* fixes include from ml docs
* dumps all the siem 7.8 stuff

* new files and corrects ml include
* includes siem index file

* fix section levels
* starts adding timeline api and object schema

* continues timeline object schema

* timeline schema

* minor edits

* another correction

* corrections - round 1

* table structure

* correction cont

* adds screenshot

* fixes terminology

* wording

* wording

* more corrections and stuff

* more stuff

* LIVERPOOL 30 YEARS

* improves screenshot callouts

* corrections are meeting

* fixes link

* restrcuture ToC

* cleanup

* improves pinned events description

* removes timeline schema file text
* adds timeline schema

* starts create timeline endpoint

* create timeline cont

* finishes api

* corrections after review

* UUID for template ID
* adds new rule fields

* makes things more readable??

* updates terminology where possible

* typos and stuff

* more terminology changes

* corrections and new eample

* updates-signals-endpoint

* missing comma

* corrections after reiew

* typo

* wording and typos

* updates update rule endpoint

* terminology

* corrections after review
* starts 7.9 updates

* updates actions api

* finalises API

* updates UI

* typo

* fixes screenshot

* corrections

* adds sn field

* adds breaking changes section

* now adds file

* title change

* corrects breaking changes

* corrections
* initial dump

* temporarily changes ml job link to allow docs built

* removes the use of the word signal

* ML rules formatting and minor text edits

* new rule formatting and edits

* missing full stop
* dtections-ui-overview

* initial overview draft

* typo

* restructuring for dedicated alerts section

* rewording

* exceptions from alerts

* adds new rule options

* adds new action text placeholder

* restructer

* structure, exceptions and building-blocks

* minor edits

* adds exceptions

* exceptions cont

* exceptions correction

* more stuff

* proofing and whatnot

* terminology

* nested exception conditions

* typo

* typo - thanks Nate

* corrections - round 1

* add nested conditions example

* typo

* editing

* more proofing

* updates ex example

* adds promoted endpoint events

* typo

* corrections after review

* corrections
* timeline and template updates

* uncomments out original timeline section in SIEM UI

* removes original timeline IDs to avoid build conflict

* add all actions screenshot

* add all actions screenshot

* corrections

* adds filter explanation and legend
* Committing first few changes.

* Committing edits 8/5/20

* Adding file to index.asciidoc

* Formatting changes 8/6/20

Co-authored-by: Janeen Mikell-Straughn <janeen.mikellstraughn@elastic.co>
* typos and links

* updates API overview links

* updates screenshots
* case connector corrections

* typo
* terminology updates

* more terminology changes

* and some more

* and some more

* and more
* Committing so I don't lose...

* Committing to save 8/12/20

* UI changes, TOC changes, creation of network page topic, edited images.

* Update network-page-overview.asciidoc

Fixing build errors.

* Fixing build errors

* Update docs/getting-started/network-page-overview.asciidoc

Co-authored-by: Lisa Cawley <lcawley@elastic.co>

* Update docs/getting-started/security-ui.asciidoc

Co-authored-by: Lisa Cawley <lcawley@elastic.co>

* Update network-page-overview.asciidoc

* Update docs/getting-started/network-page-overview.asciidoc

* Update docs/getting-started/security-ui.asciidoc

* Update docs/getting-started/security-ui.asciidoc

* [DOCS] Link fixes

* [DOCS] Nests content under Get Started

* Update docs/getting-started/network-page-overview.asciidoc

Co-authored-by: Ben Skelker <54019610+benskelker@users.noreply.github.com>

* Update docs/getting-started/security-ui.asciidoc

Co-authored-by: Ben Skelker <54019610+benskelker@users.noreply.github.com>

* Fixes/merging feedback

* Build fixes

* [DOCS] Add temporary redirects file

* [DOCS] Adds another redirect

* [DOCS] More redirects

Co-authored-by: Lisa Cawley <lcawley@elastic.co>
Co-authored-by: Ben Skelker <54019610+benskelker@users.noreply.github.com>

Co-authored-by: Lisa Cawley <lcawley@elastic.co>
Co-authored-by: Ben Skelker <54019610+benskelker@users.noreply.github.com>
* detections requirements

* removes requirements from old location

* adds cases requirements

* add case license requirement

* add ml requirements

* moves map conf and general corrections

* corrections

* terminology

* minor edits

* terminology

* adds redirect for in-app link

* adds ingest page

* minor edits

* adds link

* edit

* add alert notification license requirement

* adds link to support matrix

* edit

* adds UI pages and changes doc structure

* corrections
Co-authored-by: Janeen Mikell-Straughn <janeen.mikellstraughn@elastic.co>
brokensound77 and others added 22 commits September 7, 2021 16:29
Looks like some extra lines were accidentally left from a previous merge-conflict resolution
* [Detection-rules] Add updates for 0.14.1 package

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Adding an example request for creating a case with no connector

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
* Add docs for integration 0.14.2 rules package

* update summary for release

(cherry picked from commit db3b87d)

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
…1175)

* adds warning for basic auth only

* fixes link references

* use ref not kibana-ref, maybe?

* use kibana-ref

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
(cherry picked from commit 4b16a4f)

Co-authored-by: Devin W. Hurley <snowmiser111@gmail.com>
… detection rule execution failure (#1160) (#1222)

* Provide more details on how to start ML job to avoid ML detection rule execution failure (#1160)

* First draft

* Adds to both rule creation and troubleshooting topics
* Adds new screenshots to highlight the correct feature to use

* Update rule-start-ml-job.png

* Corrects name of custom query rule

* Update docs/troubleshooting/detections/detection-rules.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
# Conflicts:
#	docs/troubleshooting/detections/detection-rules.asciidoc

* Rearrange template-script and troubleshooting-intro
* Change ML node req from "all nodes" to "at least one" & update link

* fixes broken link

* Update docs/getting-started/ml-req.asciidoc

update link text

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
trusted-apps-list.png - TA docs page
trusted-apps-page.png - UI Overview docs page
* Add rules for integration-v0.14.3

* add summary note

* fix link

* fix file name

* remove duplicated links caused by a deprecation/rename

* update date and summary description

(cherry picked from commit d07ae02)

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Updates links to the [Filebeat Google Workspace 
module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-gsuite.html) 
so they don't break when we change the current Stack version to 8.0.

Relates to elastic/docs#2312

Co-authored-by: James Rodewig <james.rodewig@elastic.co>
Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
…ted (backport #1695) (#1716)

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
…ort #2110) (#2122)

* [DOCS] Adds warning about exceptions requiring mappings (#2110)

* Move callout about endpoint exceptions to more appropriate section

This not was previously at the top-level exceptions section, when it
really only applies when adding to the Endpoint rule.

* Add note about mappings being required for exceptions

Wording is subject to change; just throwing something at the wall for
now.

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
(cherry picked from commit aeb69a6)

# Conflicts:
#	docs/detections/detections-ui-exceptions.asciidoc

* Resolve merge conflicts with 7.14 branch.

Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
@terrancedejesus terrancedejesus requested a review from a team as a code owner November 15, 2023 18:33
Copy link

Documentation previews:

Copy link

❌ Author of the following commits did not sign a Contributor Agreement:
, b1fc7e9, 7288844, 63fc459, 09a05c4, 77e8834, eec70e8, 6d0d038, f96fd54, 05967d8, 706e3d5, 5a73632, 4893019, 7c618e7, ca994a2, 4d75d97, d3f0157, 0b9bac2, 052166d, f84e7f6, 989b244, d07583f, 64ff7df, b021041, 4d96769, 5c19287, a75eac5, , , , , , , ,

Please, read and sign the above mentioned agreement if you want to contribute to this project

Copy link
Contributor

mergify bot commented Nov 15, 2023

⚠️ The sha of the head commit of this PR conflicts with #4271. Mergify cannot evaluate rules on this PR. ⚠️

@terrancedejesus terrancedejesus deleted the fix-old-links-in-security-rules-7-14 branch November 15, 2023 18:35
Copy link
Contributor

mergify bot commented Nov 15, 2023

This pull request does not have a backport label. Could you fix it @terrancedejesus? 🙏
To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • v7.x is the label to automatically backport to the 7.x branch.
  • v7./d./d is the label to automatically backport to the 7./d branch. /d is the digit

NOTE: backport-skip has been added to this pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.