-
Notifications
You must be signed in to change notification settings - Fork 205
Closed
Labels
Docset: ESSIssues that apply to docs in the Stack releaseIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityIssues for Serverless SecurityEffort: SmallIssues that can be resolved quicklyIssues that can be resolved quicklyFeature: RulesPriority: HighIssues that are time-sensitive and/or are of high customer importanceIssues that are time-sensitive and/or are of high customer importanceTeam: Detection Enginev8.18.0
Description
Description
Alert suppression is now supported for EQL rules using sequence queries.
Background & resources
- PRs: [Security Solution][Detection Engine] Adds support for suppressing EQL sequence alerts kibana#189725
- Issues/metas: https://github.com/elastic/security-team/issues/9608
- Point of contact: @dhurley14
- Test environments: N/A
Which documentation set does this change impact?
ESS and serverless
ESS release
8.16 8.18
Serverless release
TBD
Feature differences
N/A
API docs impact
- https://www.elastic.co/guide/en/security/master/rules-api-create.html#opt-fields-alert-suppression-create: Update title
- https://www.elastic.co/guide/en/security/master/rules-api-update.html#opt-fields-alert-suppression-update: Update title
Prerequisites, privileges, feature flags
N/A
Metadata
Metadata
Assignees
Labels
Docset: ESSIssues that apply to docs in the Stack releaseIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityIssues for Serverless SecurityEffort: SmallIssues that can be resolved quicklyIssues that can be resolved quicklyFeature: RulesPriority: HighIssues that are time-sensitive and/or are of high customer importanceIssues that are time-sensitive and/or are of high customer importanceTeam: Detection Enginev8.18.0