Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add KQL search bar to the security rules management interface #130842

Open
mbudge opened this issue Apr 22, 2022 · 3 comments
Open

Add KQL search bar to the security rules management interface #130842

mbudge opened this issue Apr 22, 2022 · 3 comments
Labels
Team:Detection Rule Management Security Detection Rule Management Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@mbudge
Copy link

mbudge commented Apr 22, 2022

It would be great to see a KQL search bar in the Security > Rules page which can search more than the rule name.

  • Find newly created security rules we need to enable using the createdAt timestamp in the .kibana index. We can do a now-30d kql query to find new rules. There's over 600 rules and the created timestamp isn't available in the UI. This makes it difficult to identify new rules which have been released which we should enable. Currently we have to periodically review all 600 pre-built rules to find rules we need to clone. At the moment we have to use a python script to build a dashboard which searches the .kibana index for rules using the createdAt timestamp.

  • Filter index patterns to find rules we have data for i.e. search for winlogbeat index pattern to find rules for alerting on windows event logs. It's terribly time consuming to go through the rules to find rules we have data for, for example if we don't have registry data we want to exclude rules which require this from the rules page.

@botelastic botelastic bot added the needs-team Issues missing a team label label Apr 22, 2022
@mbudge
Copy link
Author

mbudge commented Apr 24, 2022

If KQL bar is too complicated, providing filtering in the security rule management interface on the following would help

  • Created date
  • Index patterns / requested data
  • MITRE ATT&CK™ tactic and techniques

@azasypkin azasypkin added Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team labels Apr 27, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Apr 27, 2022
@mbudge
Copy link
Author

mbudge commented Jan 15, 2024

Any update on this ER?

Is there another ticket we can track?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:Detection Rule Management Security Detection Rule Management Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

3 participants