Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] [Detections] General usability updates on rule status table #77830

Closed
dhurley14 opened this issue Sep 17, 2020 · 5 comments
Closed
Labels
Feature:Detection Rules Anything related to Security Solution's Detection Rules Feature:Rule Management Security Solution Detection Rule Management needs design review Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM Theme: rac label obsolete Theme: simp_prot_mgmt Security Solution Simplified Protection Management Theme UX Debt

Comments

@dhurley14
Copy link
Contributor

Describe the feature:

The Rule Status page could use some updates to help build a better user experience:

  • Rule status monitoring could use more sorting (I think we can add sorting to all the columns since we own the status saved object)
  • Rules status monitoring could use callouts explaining each column (I think there could be further clarification made with a callout around what a "gap" means as well as what the "last look-back date" represents)

Screen Shot 2020-09-17 at 5 18 24 PM

Describe a specific use case for the feature:

When checking for rules that are "running slowly" the analyst could sort the status monitoring table by either indexing time column or the query time column to determine rules that need better tuning.

@dhurley14 dhurley14 added review Team:SIEM Feature:Detection Rules Anything related to Security Solution's Detection Rules labels Sep 17, 2020
@dhurley14 dhurley14 self-assigned this Sep 17, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
@yctercero
Copy link
Contributor

@marrasherrier @MikePaquette - any feedback on @dhurley14 's suggestions above or possible text to be added for column descriptions?

@marrasherrier
Copy link
Contributor

@dhurley14 definitely agree that sorting and descriptions would be helpful. I can recommend some text -- is there any existing documentation explaining these columns? if not, would you be willing to explain them here? :)

@peluja1012 peluja1012 assigned banderror and unassigned dhurley14 Jan 13, 2021
@peluja1012 peluja1012 added Theme: rac label obsolete Team:Detection Rule Management Security Detection Rule Management Team needs design UX Debt Feature:Rule Management Security Solution Detection Rule Management labels Sep 14, 2021
@peluja1012 peluja1012 added the Theme: simp_prot_mgmt Security Solution Simplified Protection Management Theme label Oct 26, 2021
@MindyRS MindyRS added the Team:Detections and Resp Security Detection Response Team label Feb 23, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@peluja1012
Copy link
Contributor

Closing. Tooltips for each column were added in this PR #114023.

Additionally we have a dedicated epic for sorting and filtering. https://github.com/elastic/security-team/issues/1972

@banderror banderror removed their assignment Mar 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Detection Rules Anything related to Security Solution's Detection Rules Feature:Rule Management Security Solution Detection Rule Management needs design review Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM Theme: rac label obsolete Theme: simp_prot_mgmt Security Solution Simplified Protection Management Theme UX Debt
Projects
None yet
Development

No branches or pull requests

7 participants