Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update security solution generic timeline templates #89239

Conversation

brokensound77
Copy link
Contributor

Summary

Updated the 3 existing Generic timeline templates within the security solution to be a bit more restrictive.

Expand to see the modifications per template

endpoint

before:
image

after:
image

network

before:
image

after:
image

process

before:
image

after:
image

For maintainers

@brokensound77 brokensound77 requested review from a team as code owners January 25, 2021 22:11
@brokensound77 brokensound77 added the release_note:skip Skip the PR/issue when compiling release notes label Jan 25, 2021
@paulewing
Copy link

@brokensound77 Looks good. Only feedback would be to adjust the network template to source.ip:{source.ip} AND destination.ip:{destination.ip}. Currently the logic is an OR (likely not intended).

@brokensound77
Copy link
Contributor Author

@brokensound77 Looks good. Only feedback would be to adjust the network template to source.ip:{source.ip} AND destination.ip:{destination.ip}. Currently the logic is an OR (likely not intended).

Thanks @paulewing, just pushed the update

image

Copy link

@bm11100 bm11100 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Templated fields match what was discussed with PM. LGTM.

@kibanamachine
Copy link
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@brokensound77 brokensound77 merged commit b5b9cee into elastic:master Jan 26, 2021
brokensound77 added a commit to brokensound77/kibana that referenced this pull request Jan 26, 2021
* Update security solution generic timeline templates
brokensound77 added a commit to brokensound77/kibana that referenced this pull request Jan 26, 2021
* Update security solution generic timeline templates
@kibanamachine kibanamachine added the backport missing Added to PRs automatically when the are determined to be missing a backport. label Jan 28, 2021
@kibanamachine
Copy link
Contributor

Looks like this PR has backport PRs but they still haven't been merged. Please merge them ASAP to keep the branches relatively in sync.

2 similar comments
@kibanamachine
Copy link
Contributor

Looks like this PR has backport PRs but they still haven't been merged. Please merge them ASAP to keep the branches relatively in sync.

@kibanamachine
Copy link
Contributor

Looks like this PR has backport PRs but they still haven't been merged. Please merge them ASAP to keep the branches relatively in sync.

XavierM pushed a commit that referenced this pull request Feb 2, 2021
* Update security solution generic timeline templates

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
@kibanamachine
Copy link
Contributor

Looks like this PR has backport PRs but they still haven't been merged. Please merge them ASAP to keep the branches relatively in sync.

brokensound77 added a commit that referenced this pull request Feb 3, 2021
* Update security solution generic timeline templates
@kibanamachine kibanamachine removed the backport missing Added to PRs automatically when the are determined to be missing a backport. label Feb 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release_note:skip Skip the PR/issue when compiling release notes v7.11.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants