Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ES|QL Rules: Add Exclude matches from previous run #198529

Open
morashwan opened this issue Oct 31, 2024 · 4 comments
Open

ES|QL Rules: Add Exclude matches from previous run #198529

morashwan opened this issue Oct 31, 2024 · 4 comments
Labels
Feature:ES|QL ES|QL related features in Kibana Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)

Comments

@morashwan
Copy link

Describe the feature:
Currently the Elasticsearch Query for DSL and KQL support Exclude matches from previous run, but for ES|QL Rule this feature is missing

Describe a specific use case for the feature:
The use case is the same for DSL and KQL to prevent matching on the same alerts, and to be consistent for all search types within the same Rule category.

@botelastic botelastic bot added the needs-team Issues missing a team label label Oct 31, 2024
@wayneseymour wayneseymour added the Team:ESQL ES|QL related features in Kibana label Nov 4, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-esql (Team:ESQL)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Nov 4, 2024
@stratoula stratoula added Team:Detection Alerts Security Detection Alerts Area Team Feature:ES|QL ES|QL related features in Kibana and removed Team:ESQL ES|QL related features in Kibana labels Nov 4, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-engine (Team:Detection Alerts)

@stratoula
Copy link
Contributor

This seems to be on the security rules, def not the ESQL team area

@ymao1 ymao1 added Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) and removed Team:Detection Alerts Security Detection Alerts Area Team labels Nov 4, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/response-ops (Team:ResponseOps)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:ES|QL ES|QL related features in Kibana Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)
Projects
None yet
Development

No branches or pull requests

5 participants