Skip to content

Conversation

@joepeeples
Copy link
Contributor

@joepeeples joepeeples commented Jun 15, 2022

@madirey
Copy link

madirey commented Jun 16, 2022

Thanks for this! Upon reading, I'm thinking we may want to leave some of this information... we could still point out that the generated signals/alerts are synthetic and don't contain all the fields (only those that appear in the Threshold field configuration of the rule). Something like: NOTE: Alerts created by *threshold* rules are synthetic alerts that do not resemble the source documents. The alert itself only contains data about the fields that were aggregated over (the `Group by` fields). Other fields are omitted, because they can vary across all source documents that were counted toward the threshold. Additionally, you can reference the actual count of documents that exceeded the threshold from the `kibana.alert.threshold_result.count` field`.

@joepeeples
Copy link
Contributor Author

Thanks for the suggestion, @madirey! I added the note back in with your revisions; just let me know if anything else needs to be adjusted.

@joepeeples joepeeples requested a review from a team June 20, 2022 18:05
@joepeeples joepeeples added the readyforQA PRs that are ready for QA review. label Jun 20, 2022
@joepeeples
Copy link
Contributor Author

Adding @elastic/security-docs for a quick review, whoever gets to it first. Full team review prob not necessary.

@joepeeples joepeeples changed the title [DOCS] Remove workaround for aggregated fields in threshold rules [DOCS] Revise workaround for aggregated fields in threshold rules Jun 21, 2022
Copy link

@madirey madirey left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!!

@ghost
Copy link

ghost commented Jun 22, 2022

Hi @joepeeples ,

We tested the linked doc and found that the doc is correctly updated as per the latest UI. So we are good to go ahead and merge the changes.

Marking this ticket as 'QA validated'.

Thanks!

@ghost ghost added QA:Validated Issue has been Validated by QA Team and removed readyforQA PRs that are ready for QA review. labels Jun 22, 2022
Copy link
Contributor

@jmikell821 jmikell821 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@joepeeples joepeeples merged commit 6f0d069 into main Jun 22, 2022
mergify bot pushed a commit that referenced this pull request Jun 22, 2022
)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)
mergify bot pushed a commit that referenced this pull request Jun 22, 2022
)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)
mergify bot pushed a commit that referenced this pull request Jun 22, 2022
)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)
mergify bot pushed a commit that referenced this pull request Jun 22, 2022
)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)
joepeeples added a commit that referenced this pull request Jun 22, 2022
) (#2106)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
joepeeples added a commit that referenced this pull request Jun 22, 2022
) (#2107)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
joepeeples added a commit that referenced this pull request Jun 22, 2022
) (#2108)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
joepeeples added a commit that referenced this pull request Jun 22, 2022
) (#2109)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

(cherry picked from commit 6f0d069)

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
@joepeeples joepeeples deleted the issue-2016-threshold-rule-agg-actions branch June 22, 2022 20:45
benironside pushed a commit that referenced this pull request Jun 24, 2022
)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison
benironside added a commit that referenced this pull request Jun 28, 2022
* First draft

* Add placeholder for instructions for self-hosted

* updates formatting

* updates format and image size

* Updates formatting and annotates screenshots

* updates to the main intro and some terms here and there

* [DOCS] Revise workaround for aggregated fields in threshold rules (#2074)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

* [DOCS][8.3] Updates "Endpoint Security" to "Endpoint and Cloud Security" screenshots (#2075)

* Updates screenshots and replaces the old name with the new name.

* Updates text, fixes image names

* Update docs/getting-started/install-endpoint.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/getting-started/install-endpoint.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Fix bugs found by QA

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Add example response section (#2084)

* [DOCS] Add new EQL search configuration options (#2061)

* Update eql-rule-query-example.png

* Update procedure for creating EQL rule

* Update API docs: create rule, update rule

* Align minor phrasing

* Explain timestamp_field & timestamp_override

* Updates based on review feedback

* [DOCS] Adds warning about exceptions requiring mappings (#2110)

* Move callout about endpoint exceptions to more appropriate section

This not was previously at the top-level exceptions section, when it
really only applies when adding to the Endpoint rule.

* Add note about mappings being required for exceptions

Wording is subject to change; just throwing something at the wall for
now.

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* [DOCS] Removed ref to Stack GS (#2128)

* Minor edits to Tin's work

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Matches order of sections to order they're mentioned in the intro

* Changes bullets to numbers

* Update docs/experimental-features/experimental-features-intro.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/experimental-features-intro.asciidoc

* Incorporate Joe's and Janeen's feedback

* fixes build error

* troubleshoots build error

* troubleshoots build error

* troubleshoots build erors

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
Co-authored-by: debadair <debadair@elastic.co>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
mergify bot pushed a commit that referenced this pull request Jun 28, 2022
* First draft

* Add placeholder for instructions for self-hosted

* updates formatting

* updates format and image size

* Updates formatting and annotates screenshots

* updates to the main intro and some terms here and there

* [DOCS] Revise workaround for aggregated fields in threshold rules (#2074)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

* [DOCS][8.3] Updates "Endpoint Security" to "Endpoint and Cloud Security" screenshots (#2075)

* Updates screenshots and replaces the old name with the new name.

* Updates text, fixes image names

* Update docs/getting-started/install-endpoint.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/getting-started/install-endpoint.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Fix bugs found by QA

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Add example response section (#2084)

* [DOCS] Add new EQL search configuration options (#2061)

* Update eql-rule-query-example.png

* Update procedure for creating EQL rule

* Update API docs: create rule, update rule

* Align minor phrasing

* Explain timestamp_field & timestamp_override

* Updates based on review feedback

* [DOCS] Adds warning about exceptions requiring mappings (#2110)

* Move callout about endpoint exceptions to more appropriate section

This not was previously at the top-level exceptions section, when it
really only applies when adding to the Endpoint rule.

* Add note about mappings being required for exceptions

Wording is subject to change; just throwing something at the wall for
now.

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* [DOCS] Removed ref to Stack GS (#2128)

* Minor edits to Tin's work

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Matches order of sections to order they're mentioned in the intro

* Changes bullets to numbers

* Update docs/experimental-features/experimental-features-intro.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/experimental-features-intro.asciidoc

* Incorporate Joe's and Janeen's feedback

* fixes build error

* troubleshoots build error

* troubleshoots build error

* troubleshoots build erors

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
Co-authored-by: debadair <debadair@elastic.co>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
(cherry picked from commit edeecb9)
benironside added a commit that referenced this pull request Jun 28, 2022
* First draft

* Add placeholder for instructions for self-hosted

* updates formatting

* updates format and image size

* Updates formatting and annotates screenshots

* updates to the main intro and some terms here and there

* [DOCS] Revise workaround for aggregated fields in threshold rules (#2074)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison

* [DOCS][8.3] Updates "Endpoint Security" to "Endpoint and Cloud Security" screenshots (#2075)

* Updates screenshots and replaces the old name with the new name.

* Updates text, fixes image names

* Update docs/getting-started/install-endpoint.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/getting-started/install-endpoint.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Fix bugs found by QA

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Add example response section (#2084)

* [DOCS] Add new EQL search configuration options (#2061)

* Update eql-rule-query-example.png

* Update procedure for creating EQL rule

* Update API docs: create rule, update rule

* Align minor phrasing

* Explain timestamp_field & timestamp_override

* Updates based on review feedback

* [DOCS] Adds warning about exceptions requiring mappings (#2110)

* Move callout about endpoint exceptions to more appropriate section

This not was previously at the top-level exceptions section, when it
really only applies when adding to the Endpoint rule.

* Add note about mappings being required for exceptions

Wording is subject to change; just throwing something at the wall for
now.

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* [DOCS] Removed ref to Stack GS (#2128)

* Minor edits to Tin's work

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>

* Matches order of sections to order they're mentioned in the intro

* Changes bullets to numbers

* Update docs/experimental-features/experimental-features-intro.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/security-posture-management.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/experimental-features/experimental-features-intro.asciidoc

* Incorporate Joe's and Janeen's feedback

* fixes build error

* troubleshoots build error

* troubleshoots build error

* troubleshoots build erors

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Co-authored-by: nastasha-solomon <79124755+nastasha-solomon@users.noreply.github.com>
Co-authored-by: debadair <debadair@elastic.co>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
(cherry picked from commit edeecb9)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
acorretti pushed a commit that referenced this pull request Nov 19, 2024
)

* Remove workaround from create rule docs

* Restore admonition, with revisions from Madison
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[DOCS] Threshold Rule actions can target aggregated fields directly

4 participants