Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Detection Engine] Remove technical preview for certain rule types of alert suppression #195425

Merged
merged 9 commits into from
Oct 10, 2024

Conversation

yctercero
Copy link
Contributor

@yctercero yctercero commented Oct 8, 2024

Summary

GA-ing alert suppression for IM rule, ML rule, Threshold rule, ES|QL rule and New Terms rule. Thanks to @vitaliidm for setting up the groundwork to easily update which rules GA.

Rules that remain in technical preview are: EQL.

Screenshots below are the updated states.

Rule creation

EQL

Screenshot 2024-10-07 at 2 38 09 PM

Threshold

Screenshot 2024-10-07 at 2 41 17 PM

New terms

Screenshot 2024-10-07 at 2 38 24 PM

ES|QL

Screenshot 2024-10-07 at 2 38 34 PM

Indicator Match

Screenshot 2024-10-07 at 2 38 16 PM

Custom Query

Screenshot 2024-10-07 at 2 38 44 PM

ML

Screenshot 2024-10-09 at 1 17 26 PM
Rule details

EQL

Screenshot 2024-10-07 at 2 49 48 PM

ES|QL

Screenshot 2024-10-07 at 2 45 20 PM

Threshold

Screenshot 2024-10-07 at 2 44 18 PM

New Terms

Screenshot 2024-10-07 at 2 46 48 PM

IM

Screenshot 2024-10-07 at 2 49 11 PM

ML

Screenshot 2024-10-09 at 1 18 59 PM
Alert details

EQL

Screenshot 2024-10-08 at 7 19 59 AM

GA-ed rules

Screenshot 2024-10-08 at 7 20 15 AM

@yctercero yctercero requested review from a team as code owners October 8, 2024 14:21
@yctercero yctercero requested a review from nkhristinin October 8, 2024 14:21
@yctercero yctercero assigned yctercero and unassigned yctercero Oct 8, 2024
@yctercero yctercero added v9.0.0 v8.16.0 release_note:skip Skip the PR/issue when compiling release notes Team:Detection Engine Security Solution Detection Engine Area labels Oct 8, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-engine (Team:Detection Engine)

@yctercero yctercero added the backport:version Backport to applied version labels label Oct 8, 2024
@yctercero yctercero requested a review from approksiu October 8, 2024 14:33
@approksiu
Copy link

Let's align on ML rule type, the rest is good!

@yctercero
Copy link
Contributor Author

Let's align on ML rule type, the rest is good!

Chatted with @rylnd and GA-ing ML suppression.

@elasticmachine
Copy link
Contributor

💚 Build Succeeded

Metrics [docs]

Async chunks

Total size of all lazy-loaded chunks that will be downloaded as the user navigates the app

id before after diff
securitySolution 20.6MB 20.6MB -170.0B

Page load bundle

Size of the bundles that are downloaded on every page load. Target size is below 100kb

id before after diff
securitySolution 88.4KB 88.4KB +65.0B

History

cc @yctercero

@yctercero yctercero merged commit 65ed989 into elastic:main Oct 10, 2024
51 checks passed
@kibanamachine
Copy link
Contributor

Starting backport for target branches: 8.x

https://github.com/elastic/kibana/actions/runs/11265043811

kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Oct 10, 2024
… alert suppression (elastic#195425)

## Summary

GA-ing alert suppression for IM rule, ML rule, Threshold rule, ES|QL
rule and New Terms rule. Thanks to @vitaliidm for setting up the
groundwork to easily update which rules GA.

Rules that remain in technical preview are: EQL.

(cherry picked from commit 65ed989)
@kibanamachine
Copy link
Contributor

💚 All backports created successfully

Status Branch Result
8.x

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request Oct 10, 2024
…pes of alert suppression (#195425) (#195694)

# Backport

This will backport the following commits from `main` to `8.x`:
- [[Detection Engine] Remove technical preview for certain rule types of
alert suppression
(#195425)](#195425)

<!--- Backport version: 9.4.3 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sqren/backport)

<!--BACKPORT [{"author":{"name":"Yara
Tercero","email":"[email protected]"},"sourceCommit":{"committedDate":"2024-10-10T00:14:03Z","message":"[Detection
Engine] Remove technical preview for certain rule types of alert
suppression (#195425)\n\n## Summary\r\n\r\nGA-ing alert suppression for
IM rule, ML rule, Threshold rule, ES|QL\r\nrule and New Terms rule.
Thanks to @vitaliidm for setting up the\r\ngroundwork to easily update
which rules GA.\r\n\r\nRules that remain in technical preview are:
EQL.","sha":"65ed9899de2733ec7017ef7277bd24723131684a","branchLabelMapping":{"^v9.0.0$":"main","^v8.16.0$":"8.x","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:skip","v9.0.0","Team:Detection
Engine","v8.16.0","backport:version"],"title":"[Detection Engine] Remove
technical preview for certain rule types of alert
suppression","number":195425,"url":"https://github.com/elastic/kibana/pull/195425","mergeCommit":{"message":"[Detection
Engine] Remove technical preview for certain rule types of alert
suppression (#195425)\n\n## Summary\r\n\r\nGA-ing alert suppression for
IM rule, ML rule, Threshold rule, ES|QL\r\nrule and New Terms rule.
Thanks to @vitaliidm for setting up the\r\ngroundwork to easily update
which rules GA.\r\n\r\nRules that remain in technical preview are:
EQL.","sha":"65ed9899de2733ec7017ef7277bd24723131684a"}},"sourceBranch":"main","suggestedTargetBranches":["8.x"],"targetPullRequestStates":[{"branch":"main","label":"v9.0.0","branchLabelMappingKey":"^v9.0.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/195425","number":195425,"mergeCommit":{"message":"[Detection
Engine] Remove technical preview for certain rule types of alert
suppression (#195425)\n\n## Summary\r\n\r\nGA-ing alert suppression for
IM rule, ML rule, Threshold rule, ES|QL\r\nrule and New Terms rule.
Thanks to @vitaliidm for setting up the\r\ngroundwork to easily update
which rules GA.\r\n\r\nRules that remain in technical preview are:
EQL.","sha":"65ed9899de2733ec7017ef7277bd24723131684a"}},{"branch":"8.x","label":"v8.16.0","branchLabelMappingKey":"^v8.16.0$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Yara Tercero <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport:version Backport to applied version labels release_note:skip Skip the PR/issue when compiling release notes Team:Detection Engine Security Solution Detection Engine Area v8.16.0 v9.0.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants