[Serverless & 8.14] Updates to ES|QL Security features in 8.14 and Serverless #5149
Closed
10 tasks done
Labels
Docset: ESS
Issues that apply to docs in the Stack release
Docset: Serverless
Issues for Serverless Security
Effort: Large
Issues that require significant planning, research, writing, and testing
Priority: High
Issues that are time-sensitive and/or are of high customer importance
Team: Detection Engine
Team: GenAI
Generative AI team
Team: Threat Hunting
Formerly Data Visibility
v8.14.0
Description
Summary
With ES|QL going GA in 8.14 and being exposed in Serverless, multiple changes are being made to ESS and Serverless Security features that use ES|QL. These changes will require various doc and screenshot updates across the ESS and Serverless docsets. I've outlined them below.
ESS/8.14
The following ES|QL Security features are being updated in 8.14.
ES|QL rule -
The ES|QL rule will be moved from tech preview to GA in 8.14.
ES|QL Timeline tab
The ES|QL tab in Timeline will be moved from tech preview to GA in 8.14 and will be enabled by default.
AI Assistant Knowledge base
The entire Knowledge Base feature (which is the functionality that generates ES|QL queries and the functionality that answers questions about alerts) is still in tech preview for 8.14. Because of this, the required doc updates are slightly different. I've outlined them here.
Serverless
The following ES|QL Security features are being added to Serverless on May 6. Since Serverless is still in tech preview, these features and ES|QL will remain in tech preview.
ES|QL rule
The ES|QL rule is being added to the rule creation workflow. Users can choose the ES|QL rule type when creating a new rule.
Figure out whether the ES|QL rule docs should reference ES|QL reference content in Servlerss (which doesn't currently exist) or ES|QL content in the ESS docset. Will ping the ES writers to learn more.Confirmed that we should point to the ESS ES|QL docs if need to reference them.ES|QL Timeline tab
The ES|QL tab is being added to Timeline.
AI Assistant Knowledge base
Looks like the Knowledge base feature in Serverless can generate ES|QL queries, but the feature itself is still in the tech preview state (I'll confirm both with @benironside). The required doc updates might be the same as what I've outlined for ESS.
Background & resources
Which documentation set does this change impact?
ESS and serverless
ESS release
8.14
Serverless release
TBD
Feature differences
All details are outlined above
API docs impact
All details are outlined above
Prerequisites, privileges, feature flags
ESS/8.14
ES|QL and related ES|QL Security features will be enabled by default in 8.14 and in the GA state. Users can disable it by turning the
enableESQL
advanced setting off under the General section.Required doc updates:
Serverless
ES|QL and related ES|QL Security features (including the ES|QL option in Discover) will be enabled by default in Serverless. All ES|QL functionality in Serverless will be in Tech Preview since the Serverless platform is in Tech Preview.
No doc updates are required.
The text was updated successfully, but these errors were encountered: