-
Notifications
You must be signed in to change notification settings - Fork 188
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ESS][8.14] Alert suppression docs for EQL (non-seq) and new term rule types #5057
[ESS][8.14] Alert suppression docs for EQL (non-seq) and new term rule types #5057
Conversation
A documentation preview will be available soon. Request a new doc build by commenting
If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here. |
This pull request does not have a backport label. Could you fix it @nastasha-solomon? 🙏
NOTE: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks great! I think I found a missing noun in a list of links, but I didn't have any other feedback here.
Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Ref suppression docs in steps for creating new terms and eql rules
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left a few suggestions for your consideration 🕺
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM! 🚀
…re flags for new terms and EQL rules (#181345) ## Summary removes alert suppression feature flags for new terms and EQL rules tech doc tickets for reference: - elastic/staging-serverless-security-docs#321 - elastic/security-docs#5057
…re flags for new terms and EQL rules (elastic#181345) ## Summary removes alert suppression feature flags for new terms and EQL rules tech doc tickets for reference: - elastic/staging-serverless-security-docs#321 - elastic/security-docs#5057 (cherry picked from commit b29a27e)
…n feature flags for new terms and EQL rules (#181345) (#181873) # Backport This will backport the following commits from `main` to `8.14`: - [[Security Solution][Detection Engine] removes alert suppression feature flags for new terms and EQL rules (#181345)](#181345) <!--- Backport version: 9.4.3 --> ### Questions ? Please refer to the [Backport tool documentation](https://github.com/sqren/backport) <!--BACKPORT [{"author":{"name":"Vitalii Dmyterko","email":"92328789+vitaliidm@users.noreply.github.com"},"sourceCommit":{"committedDate":"2024-04-26T15:11:05Z","message":"[Security Solution][Detection Engine] removes alert suppression feature flags for new terms and EQL rules (#181345)\n\n## Summary\r\n\r\nremoves alert suppression feature flags for new terms and EQL rules\r\n\r\n\r\ntech doc tickets for reference: \r\n- https://github.com/elastic/staging-serverless-security-docs/pull/321\r\n- https://github.com/elastic/security-docs/pull/5057","sha":"b29a27ebf0090247e4273e2bd281c2d025a281b0","branchLabelMapping":{"^v8.15.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:skip","Team:Detections and Resp","Team: SecuritySolution","backport:prev-minor","Team:Detection Engine","v8.15.0"],"title":"[Security Solution][Detection Engine] removes alert suppression feature flags for new terms and EQL rules","number":181345,"url":"https://github.com/elastic/kibana/pull/181345","mergeCommit":{"message":"[Security Solution][Detection Engine] removes alert suppression feature flags for new terms and EQL rules (#181345)\n\n## Summary\r\n\r\nremoves alert suppression feature flags for new terms and EQL rules\r\n\r\n\r\ntech doc tickets for reference: \r\n- https://github.com/elastic/staging-serverless-security-docs/pull/321\r\n- https://github.com/elastic/security-docs/pull/5057","sha":"b29a27ebf0090247e4273e2bd281c2d025a281b0"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v8.15.0","branchLabelMappingKey":"^v8.15.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/181345","number":181345,"mergeCommit":{"message":"[Security Solution][Detection Engine] removes alert suppression feature flags for new terms and EQL rules (#181345)\n\n## Summary\r\n\r\nremoves alert suppression feature flags for new terms and EQL rules\r\n\r\n\r\ntech doc tickets for reference: \r\n- https://github.com/elastic/staging-serverless-security-docs/pull/321\r\n- https://github.com/elastic/security-docs/pull/5057","sha":"b29a27ebf0090247e4273e2bd281c2d025a281b0"}}]}] BACKPORT--> Co-authored-by: Vitalii Dmyterko <92328789+vitaliidm@users.noreply.github.com>
…e types (#5057) * Update alert-suppression.asciidoc * Update docs/detections/alert-suppression.asciidoc * Adding more to draft * Minor typo * Aligning with Serverless docs * Update docs/detections/alert-suppression.asciidoc Co-authored-by: Ryland Herrick <ryalnd@gmail.com> * Update docs/detections/api/rules/rules-api-create.asciidoc * Updating update api * Fixed formatting error * Ben's input pt 1 * Ref suppression docs Ref suppression docs in steps for creating new terms and eql rules * Re-adding content to avoid conflict * Update docs/detections/api/rules/rules-api-create.asciidoc * Updating titles * Vitalii's input * ben's input * Update docs/detections/api/rules/rules-api-update.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/api/rules/rules-api-create.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/alert-suppression.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/api/rules/rules-api-create.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/api/rules/rules-api-update.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> --------- Co-authored-by: Ryland Herrick <ryalnd@gmail.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> (cherry picked from commit 2fd85dd)
…erm rule types (backport #5057) (#5142) * Update alert-suppression.asciidoc * Update docs/detections/alert-suppression.asciidoc * Adding more to draft * Minor typo * Aligning with Serverless docs * Update docs/detections/alert-suppression.asciidoc Co-authored-by: Ryland Herrick <ryalnd@gmail.com> * Update docs/detections/api/rules/rules-api-create.asciidoc * Updating update api * Fixed formatting error * Ben's input pt 1 * Ref suppression docs Ref suppression docs in steps for creating new terms and eql rules * Re-adding content to avoid conflict * Update docs/detections/api/rules/rules-api-create.asciidoc * Updating titles * Vitalii's input * ben's input * Update docs/detections/api/rules/rules-api-update.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/api/rules/rules-api-create.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/alert-suppression.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/api/rules/rules-api-create.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/api/rules/rules-api-update.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> --------- Co-authored-by: Ryland Herrick <ryalnd@gmail.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> (cherry picked from commit 2fd85dd) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
Contributes to #4977 and #5030
Previews:
Twin serverless PR: https://github.com/elastic/staging-serverless-security-docs/pull/321