-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Labels
Feature: RulesTeam: Detections/ResponseDetections and ResponseDetections and ResponseTeam: Docsv8.3.0
Description
Description
When creating a new event correlation detection rule, there are three new configuration options for EQL queries (per elastic/kibana#132247):
- Event category field - Allows user to modify the categorization field to classify different types of events
- Tiebreaker field - Used to sort hits with the same timestamp in ascending order
- Timestamp field - Controls how documents are sorted within the result set
Checklist
- Update procedure to include new options: https://www.elastic.co/guide/en/security/master/rules-ui-create.html#create-eql-rule
- Links to Elasticsearch/EQL docs on timestamp and event category field and tiebreaker field
- Update screenshot to include new icon: https://www.elastic.co/guide/en/security/master/images/eql-rule-query-example.png
- Update API topics, including new settings as optional fields:
Screenshot
Metadata
Metadata
Assignees
Labels
Feature: RulesTeam: Detections/ResponseDetections and ResponseDetections and ResponseTeam: Docsv8.3.0
