Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ESS][8.14] Alert suppression docs for EQL (non-seq) and new term rule types #5057

Merged
merged 25 commits into from
Apr 30, 2024

Conversation

nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Apr 5, 2024

Contributes to #4977 and #5030

Previews:

Twin serverless PR: https://github.com/elastic/staging-serverless-security-docs/pull/321

@nastasha-solomon nastasha-solomon requested a review from a team as a code owner April 5, 2024 18:17
Copy link

github-actions bot commented Apr 5, 2024

A documentation preview will be available soon.

Request a new doc build by commenting
  • Rebuild this PR: run docs-build
  • Rebuild this PR and all Elastic docs: run docs-build rebuild

run docs-build is much faster than run docs-build rebuild. A rebuild should only be needed in rare situations.

If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here.

Copy link
Contributor

mergify bot commented Apr 5, 2024

This pull request does not have a backport label. Could you fix it @nastasha-solomon? 🙏
To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • v7.x is the label to automatically backport to the 7.x branch.
  • v7./d./d is the label to automatically backport to the 7./d branch. /d is the digit

NOTE: backport-skip has been added to this pull request.

@mergify mergify bot added the backport-skip label Apr 5, 2024
@nastasha-solomon nastasha-solomon added Team: Detection Engine Priority: High Issues that are time-sensitive and/or are of high customer importance Effort: Small Issues that can be resolved quickly v8.14.0 and removed backport-skip labels Apr 11, 2024
@nastasha-solomon nastasha-solomon self-assigned this Apr 11, 2024
@nastasha-solomon nastasha-solomon marked this pull request as draft April 11, 2024 01:44
@nastasha-solomon nastasha-solomon changed the title [ESS] Alert suppression docs for EQL (non-seq) and new term rule types [ESS][8.14] Alert suppression docs for EQL (non-seq) and new term rule types Apr 11, 2024
rylnd
rylnd previously approved these changes Apr 11, 2024
Copy link
Contributor

@rylnd rylnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great! I think I found a missing noun in a list of links, but I didn't have any other feedback here.

docs/detections/alert-suppression.asciidoc Outdated Show resolved Hide resolved
docs/detections/alert-suppression.asciidoc Show resolved Hide resolved
@vitaliidm vitaliidm self-requested a review April 12, 2024 08:54
vitaliidm
vitaliidm previously approved these changes Apr 12, 2024
docs/detections/alert-suppression.asciidoc Show resolved Hide resolved
@nastasha-solomon nastasha-solomon dismissed stale reviews from vitaliidm and rylnd via e91fc63 April 12, 2024 16:28
benironside
benironside previously approved these changes Apr 24, 2024
Copy link
Contributor

@benironside benironside left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a few suggestions for your consideration 🕺

docs/detections/alert-suppression.asciidoc Outdated Show resolved Hide resolved
docs/detections/api/rules/rules-api-create.asciidoc Outdated Show resolved Hide resolved
docs/detections/api/rules/rules-api-create.asciidoc Outdated Show resolved Hide resolved
docs/detections/api/rules/rules-api-update.asciidoc Outdated Show resolved Hide resolved
docs/detections/api/rules/rules-api-update.asciidoc Outdated Show resolved Hide resolved
nastasha-solomon and others added 6 commits April 24, 2024 16:49
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! 🚀

vitaliidm added a commit to elastic/kibana that referenced this pull request Apr 26, 2024
…re flags for new terms and EQL rules (#181345)

## Summary

removes alert suppression feature flags for new terms and EQL rules


tech doc tickets for reference: 
- elastic/staging-serverless-security-docs#321
- elastic/security-docs#5057
kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Apr 26, 2024
…re flags for new terms and EQL rules (elastic#181345)

## Summary

removes alert suppression feature flags for new terms and EQL rules

tech doc tickets for reference:
- elastic/staging-serverless-security-docs#321
- elastic/security-docs#5057

(cherry picked from commit b29a27e)
kibanamachine referenced this pull request in elastic/kibana Apr 26, 2024
…n feature flags for new terms and EQL rules (#181345) (#181873)

# Backport

This will backport the following commits from `main` to `8.14`:
- [[Security Solution][Detection Engine] removes alert suppression
feature flags for new terms and EQL rules
(#181345)](#181345)

<!--- Backport version: 9.4.3 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sqren/backport)

<!--BACKPORT [{"author":{"name":"Vitalii
Dmyterko","email":"92328789+vitaliidm@users.noreply.github.com"},"sourceCommit":{"committedDate":"2024-04-26T15:11:05Z","message":"[Security
Solution][Detection Engine] removes alert suppression feature flags for
new terms and EQL rules (#181345)\n\n## Summary\r\n\r\nremoves alert
suppression feature flags for new terms and EQL rules\r\n\r\n\r\ntech
doc tickets for reference: \r\n-
https://github.com/elastic/staging-serverless-security-docs/pull/321\r\n-
https://github.com/elastic/security-docs/pull/5057","sha":"b29a27ebf0090247e4273e2bd281c2d025a281b0","branchLabelMapping":{"^v8.15.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:skip","Team:Detections
and Resp","Team: SecuritySolution","backport:prev-minor","Team:Detection
Engine","v8.15.0"],"title":"[Security Solution][Detection Engine]
removes alert suppression feature flags for new terms and EQL
rules","number":181345,"url":"https://github.com/elastic/kibana/pull/181345","mergeCommit":{"message":"[Security
Solution][Detection Engine] removes alert suppression feature flags for
new terms and EQL rules (#181345)\n\n## Summary\r\n\r\nremoves alert
suppression feature flags for new terms and EQL rules\r\n\r\n\r\ntech
doc tickets for reference: \r\n-
https://github.com/elastic/staging-serverless-security-docs/pull/321\r\n-
https://github.com/elastic/security-docs/pull/5057","sha":"b29a27ebf0090247e4273e2bd281c2d025a281b0"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v8.15.0","branchLabelMappingKey":"^v8.15.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/181345","number":181345,"mergeCommit":{"message":"[Security
Solution][Detection Engine] removes alert suppression feature flags for
new terms and EQL rules (#181345)\n\n## Summary\r\n\r\nremoves alert
suppression feature flags for new terms and EQL rules\r\n\r\n\r\ntech
doc tickets for reference: \r\n-
https://github.com/elastic/staging-serverless-security-docs/pull/321\r\n-
https://github.com/elastic/security-docs/pull/5057","sha":"b29a27ebf0090247e4273e2bd281c2d025a281b0"}}]}]
BACKPORT-->

Co-authored-by: Vitalii Dmyterko <92328789+vitaliidm@users.noreply.github.com>
@nastasha-solomon nastasha-solomon merged commit 2fd85dd into main Apr 30, 2024
3 checks passed
mergify bot pushed a commit that referenced this pull request Apr 30, 2024
…e types (#5057)

* Update alert-suppression.asciidoc

* Update docs/detections/alert-suppression.asciidoc

* Adding more to draft

* Minor typo

* Aligning with Serverless docs

* Update docs/detections/alert-suppression.asciidoc

Co-authored-by: Ryland Herrick <ryalnd@gmail.com>

* Update docs/detections/api/rules/rules-api-create.asciidoc

* Updating update api

* Fixed formatting error

* Ben's input pt 1

* Ref suppression docs

Ref suppression docs in steps for creating new terms and eql rules

* Re-adding content to avoid conflict

* Update docs/detections/api/rules/rules-api-create.asciidoc

* Updating titles

* Vitalii's input

* ben's input

* Update docs/detections/api/rules/rules-api-update.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/api/rules/rules-api-create.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/alert-suppression.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/api/rules/rules-api-create.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/api/rules/rules-api-update.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

---------

Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
(cherry picked from commit 2fd85dd)
nastasha-solomon added a commit that referenced this pull request Apr 30, 2024
…erm rule types (backport #5057) (#5142)

* Update alert-suppression.asciidoc

* Update docs/detections/alert-suppression.asciidoc

* Adding more to draft

* Minor typo

* Aligning with Serverless docs

* Update docs/detections/alert-suppression.asciidoc

Co-authored-by: Ryland Herrick <ryalnd@gmail.com>

* Update docs/detections/api/rules/rules-api-create.asciidoc

* Updating update api

* Fixed formatting error

* Ben's input pt 1

* Ref suppression docs

Ref suppression docs in steps for creating new terms and eql rules

* Re-adding content to avoid conflict

* Update docs/detections/api/rules/rules-api-create.asciidoc

* Updating titles

* Vitalii's input

* ben's input

* Update docs/detections/api/rules/rules-api-update.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/api/rules/rules-api-create.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/alert-suppression.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/api/rules/rules-api-create.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

* Update docs/detections/api/rules/rules-api-update.asciidoc

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>

---------

Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
(cherry picked from commit 2fd85dd)

Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
@nastasha-solomon nastasha-solomon mentioned this pull request May 16, 2024
22 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Effort: Small Issues that can be resolved quickly Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine v8.14.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants