Skip to content

[Meta] Update rules to account for Elastic Agent logs index #255

@bm11100

Description

@bm11100

Description

If using the Elastic Agent, the events go into the logs-* index. All rule types that also have an Agent integration (example - AWS) will need to be updated/reviewed to ensure they work correctly with a standalone beat and the Elastic Agent index pattern. For the AWS example, need to add logs-aws* to each rule.

Roadmap - https://github.com/elastic/security-team/issues/224 and https://github.com/elastic/siem-team/issues/767

Review rule types

For 7.10

For 7.11

For 7.12

TBD

  • Cross-platform
    Agent integration:
    PR (if applicable):
  • Network
    Agent integration:
    PR (if applicable):
  • ML Jobs
    PR (if applicable):

Example

index = ["filebeat-*", "logs-aws*"]

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Rule: Tuningtweaking or tuning an existing rulestale60 days of inactivityv7.11.0v7.12.07.12 rules release packagev7.13.07.13 rules release package

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions