Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Exceptions] Notify users of outdated exceptions #96469

Open
yctercero opened this issue Apr 7, 2021 · 3 comments
Open

[Security Solution][Exceptions] Notify users of outdated exceptions #96469

yctercero opened this issue Apr 7, 2021 · 3 comments
Assignees
Labels
Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Detection Rules Anything related to Security Solution's Detection Rules Feature:Rule Exceptions Security Solution Rule Exceptions feature Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. UX

Comments

@yctercero
Copy link
Contributor

Describe the feature:

When a user creates an exception that uses large value lists, we check that the field selected matches the type of the list. So only large value lists of type keyword appear for keyword fields, large value lists of type ip for ip fields, etc...

If a user update their mapping from keyword/text to just keyword when they revisit their exceptions it would appear as if though their lists are no longer there (because of the type mismatch that now exists).

Describe a specific use case for the feature:
Alerting the user with a badge that warns them of this on exceptions where we see there is now a mismatch would be extremely helpful. Unless a user checks their exceptions, they may not realize that the exception is no longer valid.

@botelastic botelastic bot added the needs-team Issues missing a team label label Apr 7, 2021
@yctercero yctercero added Feature:Detection Rules Anything related to Security Solution's Detection Rules Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Rule Exceptions Security Solution Rule Exceptions feature Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detections and Resp Security Detection Response Team UX and removed needs-team Issues missing a team label labels Apr 7, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@yctercero
Copy link
Contributor Author

Note: Recent case of user running into this issue. Initially thought it was a bug with exceptions, but was a mapping issue described above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Detection Rules Anything related to Security Solution's Detection Rules Feature:Rule Exceptions Security Solution Rule Exceptions feature Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. UX
Projects
None yet
Development

No branches or pull requests

3 participants