Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Serverless]: Security – Create a detection rule #6154

Open
natasha-moore-elastic opened this issue Nov 13, 2024 · 0 comments
Open

[Serverless]: Security – Create a detection rule #6154

natasha-moore-elastic opened this issue Nov 13, 2024 · 0 comments
Assignees
Labels
bug Something isn't working Docset: Serverless Issues for Serverless Security Team: Detection Engine Team: Threat Hunting Formerly Data Visibility

Comments

@natasha-moore-elastic
Copy link
Contributor

Serverless Docs

Elastic Security

Description

  • The section on machine learning rules goes before the custom query rules section, but in the UI, the custom query rule type comes first.

  • The Timeline template field at the end of the define rule section isn’t described for any of the rules.

  • "Before you create rules, create Timeline templates so they can be selected here." – Timeline templates should link to https://www.elastic.co/guide/en/serverless/current/security-timeline-templates-ui.html. It’s also unclear from the screenshot and surrounding text where exactly Timeline templates can be selected. Does this refer to the Timeline template field at the end of the define rule section?

  • "You can use saved queries and queries from saved Timelines (Import query from saved Timeline) as rule conditions." – I don’t see the saved queries icon in the UI.

  • "Continue onto setting up alert notifications" – should link to the Set up rule actions (optional) section.

  • "Project settings → Management → Connectors" – should be Project settings → Stack Management → Connectors.

  • "Select the Show Elasticsearch Serverless requests, ran during rule executions option" – In the UI, the option is called Show Elasticsearch requests, ran during rule executions.

Resources and additional context

https://www.elastic.co/guide/en/serverless/current/security-rules-create.html

@georgewallace georgewallace transferred this issue from elastic/docs-content Nov 13, 2024
@nastasha-solomon nastasha-solomon self-assigned this Nov 13, 2024
@nastasha-solomon nastasha-solomon added bug Something isn't working Docset: Serverless Issues for Serverless Security labels Nov 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Docset: Serverless Issues for Serverless Security Team: Detection Engine Team: Threat Hunting Formerly Data Visibility
Projects
None yet
Development

No branches or pull requests

4 participants