Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scripted Fields are not supported by SIEM Detections Rules #97778

Open
Tracked by #165878
gaby opened this issue Apr 21, 2021 · 3 comments
Open
Tracked by #165878

Scripted Fields are not supported by SIEM Detections Rules #97778

gaby opened this issue Apr 21, 2021 · 3 comments
Labels
enhancement New value added to drive a business result Feature:Detection Alerts Security Solution Detection Alerts Feature impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@gaby
Copy link

gaby commented Apr 21, 2021

Kibana version:
7.12.0

Elasticsearch version:
7.12.0

Server OS version:
Ubuntu Focal 20.04 LTS

Original install method (e.g. download page, yum, from source, etc.):
Docker

Describe the bug:
Currently when creating detection rules in SIEM, scripted fields are not supported.

Steps to reproduce:

  1. Create scripted field in an index pattern
  2. Try to create a SIEM Detection Query using this scripted field
  3. Field won't show in the list.

Expected behavior:
Scripted fields to be supported by SIEM

@gaby gaby added the bug Fixes for quality problems that affect the customer experience label Apr 21, 2021
@botelastic botelastic bot added the needs-team Issues missing a team label label Apr 21, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@botelastic botelastic bot removed the needs-team Issues missing a team label label May 12, 2021
@spong spong added Team:Detections and Resp Security Detection Response Team triage_needed labels May 12, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@MadameSheema MadameSheema added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label May 12, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@MadameSheema MadameSheema added impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. and removed triage_needed labels May 12, 2021
@peluja1012 peluja1012 added Feature:Detection Alerts Security Solution Detection Alerts Feature Team:Detection Alerts Security Detection Alerts Area Team labels Mar 18, 2022
@marshallmain marshallmain added enhancement New value added to drive a business result Team:Security Solution Platform Security Solution Platform Team and removed bug Fixes for quality problems that affect the customer experience Team:Detection Alerts Security Detection Alerts Area Team labels Mar 29, 2022
@peluja1012 peluja1012 added impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. and removed impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. labels May 6, 2022
@jethr0null jethr0null reopened this Aug 17, 2022
@yctercero yctercero added Team:Detection Engine Security Solution Detection Engine Area and removed Team:Security Solution Platform Security Solution Platform Team labels May 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Detection Alerts Security Solution Detection Alerts Feature impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

9 participants