Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Alerts] Log actual queries executed by detection engine #141463

Open
Tracked by #165878
marshallmain opened this issue Sep 22, 2022 · 1 comment
Open
Tracked by #165878
Labels
enhancement New value added to drive a business result Team:Detection Engine Security Solution Detection Engine Area Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@marshallmain
Copy link
Contributor

In some cases the detection engine dynamically loads data by reference that becomes part of the rule's query logic. Current examples include saved queries and exceptions. We don't keep detailed records of the generated queries in the alerts for each rule execution, instead the alerts only contain the IDs that reference the dynamically loaded data.

As a result, it's impossible to accurately reproduce a detection rule query from an alert document if the saved query/exception items have changed since the alert was generated. It would be good to build a record of the actual generated query, including the dynamically loaded portions.

@marshallmain marshallmain added enhancement New value added to drive a business result Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Alerts Security Detection Alerts Area Team labels Sep 22, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@yctercero yctercero added Team:Detection Engine Security Solution Detection Engine Area and removed Team:Detection Alerts Security Detection Alerts Area Team labels May 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Team:Detection Engine Security Solution Detection Engine Area Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

3 participants