Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
bbeced0
First draft
nastasha-solomon Sep 30, 2024
390b265
Serverless first draft
nastasha-solomon Sep 30, 2024
24e750f
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Sep 30, 2024
2e6f291
Fixing typos
nastasha-solomon Oct 1, 2024
b9183d4
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Oct 1, 2024
de269cc
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Oct 1, 2024
d9b849c
Vitalii's input
nastasha-solomon Oct 1, 2024
3172a1e
Updated anchor text
nastasha-solomon Oct 1, 2024
1194e07
Updated title
nastasha-solomon Oct 1, 2024
fc2390a
Minor changes
nastasha-solomon Oct 1, 2024
56ef20a
Removed extra the
nastasha-solomon Oct 1, 2024
6c7d87c
Fix conflict
nastasha-solomon Oct 1, 2024
2967d20
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Oct 1, 2024
bd98d1e
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Oct 1, 2024
d985ca3
Vitalii's feedback round 2
nastasha-solomon Oct 1, 2024
fdc7dd0
var fixes
nastasha-solomon Oct 1, 2024
ef045cd
Active voice
nastasha-solomon Oct 1, 2024
2be3231
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Oct 2, 2024
d2b73bd
Update docs/serverless/rules/rules-ui-create.mdx
nastasha-solomon Oct 2, 2024
ffb767f
Update docs/detections/rules-ui-create.asciidoc
nastasha-solomon Oct 2, 2024
45e2aef
Update docs/serverless/rules/rules-ui-create.mdx
nastasha-solomon Oct 2, 2024
087731c
Update docs/serverless/rules/rules-ui-create.mdx
nastasha-solomon Oct 2, 2024
8883ee5
Update slug
nastasha-solomon Oct 2, 2024
bfca164
slugslugslug
nastasha-solomon Oct 3, 2024
fb32e07
Merge branch 'main' into issue-5844-logged-es-request-rule-preview
nastasha-solomon Oct 3, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions docs/detections/rules-ui-create.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -820,3 +820,21 @@ TIP: Avoid setting long time ranges with short rule intervals, or the rule previ

* To close the preview, click the *Rule preview* button again.

[discrete]
[[view-rule-es-queries]]
==== View your rule's {es} queries (optional)

NOTE: This option is only offered for {esql} and event correlation rules.

When previewing a rule, you can also learn about its {es} queries, which are submitted when the rule runs. This information can help you identify and troubleshoot potential rule issues. You can also use it to confirm that your rule is retrieving the expected data.

To learn more about your rule's {es} queries, preview its results and do the following:

. Select the **Show {es} requests, ran during rule executions** option below the preview's date and time picker. The **Preview logged results** section displays under the histogram and alerts table.
. Click the **Preview logged results** section to expand it. Within the section, each rule execution is shown on an individual row.
. Expand each row to learn more about the {es} queries that the rule submits each time it executes. The following details are provided:
** When the rule execution started, and how long it took to complete
** A brief explanation of what the {es} queries do
** The actual {es} queries that the rule submits to indices containing events that are used during the rule execution
+
TIP: Run the queries in {kibana-ref}/console-kibana.html[Console] to determine if your rule is retrieving the expected data. For example, to test your rule’s exceptions, run the rule’s {es} queries, which will also contain exceptions added to the rule. If your rule’s exceptions are working as intended, the query will not return events that should be ignored.
22 changes: 22 additions & 0 deletions docs/serverless/rules/rules-ui-create.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -875,3 +875,25 @@ To interact with the rule preview:

* To close the preview, click the **Rule preview** button again.

<div id="view-rule-es-queries"></div>

### View your rule's ((es)) queries (optional)

<DocCallOut title="Note">
This option is only offered for ((esql)) and event correlation rules.
</DocCallOut>

When previewing a rule, you can also learn about its ((es)) queries, which are submitted when the rule runs. This information can help you identify and troubleshoot potential rule issues. You can also use it to confirm that your rule is retrieving the expected data.

To learn more about your rule's ((es)) queries, preview its results and do the following:

1. Select the **Show ((es)) requests, ran during rule executions** option below the preview's date and time picker. The **Preview logged results** section displays under the histogram and alerts table.
1. Click the **Preview logged results** section to expand it. Within the section, each rule execution is shown on an individual row.
1. Expand each row to learn more about the ((es)) queries that the rule submits each time it executes. The following details are provided:
* When it started, and how long it took to complete
* A brief explanation of what the ((es)) queries do
* The actual ((es)) queries that the rule submits to indices containing events that are used during the rule execution

<DocCallOut title="Tip">
Run the queries in <DocLink slug="/serverless/devtools/run-api-requests-in-the-console">Console</DocLink> to determine if your rule is retrieving the expected data. For example, to test your rule’s exceptions, run the rule’s ((es)) queries, which will also contain exceptions added to the rule. If your rule’s exceptions are working as intended, the query will not return events that should be ignored.
</DocCallOut>
Loading