Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEATURE] Security Analytics: Inlcude findings as ctx.results #696

Open
agoerl opened this issue Oct 26, 2023 · 2 comments
Open

[FEATURE] Security Analytics: Inlcude findings as ctx.results #696

agoerl opened this issue Oct 26, 2023 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@agoerl
Copy link

agoerl commented Oct 26, 2023

Is your feature request related to a problem?
ctx.results is present in alerts but always empty. Enriching detector alerts with details from findings is not possible.

What solution would you like?
In Alerting ctx.results is populated and can be used. Including findings as ctx.results in Security Analytics would be consistent with the behaviour in Alerting. Also, including details from the findings via ctx.results in the trigger message would greatly improve alerting workflows.

What alternatives have you considered?
I do not see an alternative, since the information is currently just not available.

Do you have any additional context?
I am referring to the feature set of OpenSearch 2.10 using notification messages in alert trigger in the Security Analytics plugin.

@agoerl agoerl added enhancement New feature or request untriaged labels Oct 26, 2023
@gabrielssant0s
Copy link

gabrielssant0s commented Feb 26, 2024

Including findings like ctx.results in Security Analytics would be a game changer. For specific scenarios, not having ctx.results in Security Analytics makes it unfeasible to use, as the output is very poor.

Is there a roadmap for this to be implemented?

@jimishs
Copy link

jimishs commented Apr 2, 2024

Hi @agoerl and @gabrielssant0s . Yes we are tracking this issue, but dont have a timeline to provide. Agree that this will be a useful enhancement. There are some other requests on alert enrichment with more context from the findings / document as well. We are evaluating these requests together.

@praveensameneni praveensameneni added this to Backlog (Feature Requests, Enhancements) in Security Analytics Roadmap Apr 10, 2024
@praveensameneni praveensameneni moved this from Backlog (Feature Requests, Enhancements) to 6-month roadmap in Security Analytics Roadmap May 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Development

No branches or pull requests

5 participants