-
Notifications
You must be signed in to change notification settings - Fork 517
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Include all historical rule versions in the prebuilt rules package #4311
Comments
We have filtered the assets to exclude deprecated rules to use for 8.17.2 package
cc @Mikaayenson |
When creating a beta package for 8.17.2 - elastic/integrations#12261 We observed many files having mismatched ID from file name that causes error like below
We used the below script to correct them
|
Once these corrections are done and adding all historical rules which are not depracated and the latest rules from current release we have about 11455 rules
Spot checked some of the missing rules from issue -#4312 These rules were present. |
BetPackage Live - https://epr.elastic.co/package/security_detection_engine/8.17.2-beta.2/ with 11455 Rules |
Since the rule package version
8.17.1
does not include all historical rule versions, I’ve downloaded all published rule packages compatible with Kibana8.x
and consolidated all previously published rule versions into a single package: security_detection_engine-8.17.2.zip1.0.1
to8.17.1
.I tested the package locally, and it resolves the issue with missing base rule versions observed earlier. We should use this package as the basis for releasing future packages that include the full rule history.
The text was updated successfully, but these errors were encountered: