Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Import Saved Search in Detections Rule #81566

Open
jaredstewart101 opened this issue Oct 23, 2020 · 1 comment
Open

Import Saved Search in Detections Rule #81566

jaredstewart101 opened this issue Oct 23, 2020 · 1 comment
Labels
enhancement New value added to drive a business result Feature:Detection Rules Anything related to Security Solution's Detection Rules Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@jaredstewart101
Copy link

Describe the feature:

Similar to how you can create a visualization in Kibana using a "Saved Search", when you're creating a Custom Rule in Detections you should be able to import query from a "Saved Search".

Describe a specific use case for the feature:

This would be helpful while creating custom rules because right now you have to do the search somewhere else and copy and paste it into the Custom Rule. If you were able to do the search in Discover and save it, you'd be able to import it easier when creating a Custom Rule in Detections.

@kindsun kindsun added enhancement New value added to drive a business result Feature:Detection Rules Anything related to Security Solution's Detection Rules Team:SIEM labels Nov 5, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Nov 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Detection Rules Anything related to Security Solution's Detection Rules Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

4 participants