Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Discussion - Security Profile experience for security users in One Discover #189897

Open
logeekal opened this issue Aug 5, 2024 · 3 comments
Assignees
Milestone

Comments

@logeekal
Copy link
Contributor

logeekal commented Aug 5, 2024

Summary

Currently, One Discover does not gives security solution a way to know if a user is a security user or not. This might result in below issues:

Profile Conflict

Security wants to give users a "Security Experience" for all the events irrespective of where that event originated. For example, that event could be a log event or an event from any of the beats.

For simplicity, if we assume it is a log event, then it is difficult for One Discover to know which profile should take precedence because that event is relevant to both Security and O11y.

Data Source Profile Resolution

Since security does not have any particular index ( in addition to .alerts-security*) it wants to look at, users of security can create their custom data view and may look at any index they want.

Because of this, it is not straightforward to create any kind of heuristics to determine whether the security profile should be activated.

Possible Solutions

  1. Allow users to explicitly select the experience?
  2. Discover should open in the subpath of an app such as /app/security/discover... or /app/o11y/discover...
@botelastic botelastic bot added the needs-team Issues missing a team label label Aug 5, 2024
@logeekal logeekal changed the title [One Discover] - Security Profile experience for security users in One Discover [One Discover] - Discussion - Security Profile experience for security users in One Discover Aug 5, 2024
@logeekal logeekal changed the title [One Discover] - Discussion - Security Profile experience for security users in One Discover [One Discover] Discussion - Security Profile experience for security users in One Discover Aug 5, 2024
@logeekal logeekal added the Team:Threat Hunting:Investigations Security Solution Investigations Team label Aug 5, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Aug 5, 2024
@logeekal logeekal added this to the 8.16 milestone Aug 5, 2024
@ninoslavmiskovic
Copy link
Contributor

@logeekal - We are tracking a contextual data presentation for Security users as part of the One Discover Program, so let's bring this to the sync. I will watch the recordings if it already have been shared, while I was on PTO.

@logeekal
Copy link
Contributor Author

logeekal commented Aug 6, 2024

Thanks @ninoslavmiskovic for taking a look. It was not shared while you were away and that is why I added this point in this week's agenda just to get discussions started. @michaelolo24 will be talking about it as I have a vacation in Germany on Thursday.

@logeekal logeekal changed the title [One Discover] Discussion - Security Profile experience for security users in One Discover [Security Solution] Discussion - Security Profile experience for security users in One Discover Oct 17, 2024
@PhilippeOberti PhilippeOberti modified the milestones: 8.16, 8.17 Oct 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants