Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Bring Alert Grouping Feature into GA #152134

Closed
10 of 11 tasks
stephmilovic opened this issue Feb 24, 2023 · 2 comments
Closed
10 of 11 tasks

[Security Solution] Bring Alert Grouping Feature into GA #152134

stephmilovic opened this issue Feb 24, 2023 · 2 comments
Assignees
Labels
8.8 candidate Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting:Explore Team:Threat Hunting Security Solution Threat Hunting Team v8.8.0

Comments

@stephmilovic
Copy link
Contributor

stephmilovic commented Feb 24, 2023

Alert grouping was introduced as Technical Preview in 8.7. There are a few tasks we need to take care of before the feature reaches General Availability.

Product owner: @paulewing
Designer: ??? ask @YulNaumenko
Teams impacted: explore (@YulNaumenko), detections (@logeekal )

1. Unit test coverage

  • x-pack/plugins/security_solution/public/detections/components/alerts_table/grouped_alerts.tsx

2. Bug fixes

3. User flow fixes

  • A user only has one rule and it is building block. Toggle it off, all groups disappear and query empty. You have no way to toggle it back on unless you add a new rule to bring a group back and toggle it back on. This video sort of demonstrates that, but luckily in this scenario we have other rules we can use to bring it back

    uhoh2.mov

4. Cypress tests

Last. Remove beta label

  • Remove BETA label from feature:
    Screenshot 2023-02-27 at 8 25 23 PM
@stephmilovic stephmilovic added Team:Threat Hunting Security Solution Threat Hunting Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting:Explore v8.8.0 labels Feb 24, 2023
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
8.8 candidate Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting:Explore Team:Threat Hunting Security Solution Threat Hunting Team v8.8.0
Projects
None yet
Development

No branches or pull requests

3 participants