Skip to content

Commit

Permalink
[8.9] [DOCS] Document the new rule execution status filter (backport #…
Browse files Browse the repository at this point in the history
…3570) (#3580)

Co-authored-by: natasha-moore-elastic <[email protected]>
Co-authored-by: Nastasha Solomon <[email protected]>
  • Loading branch information
3 people authored Jul 18, 2023
1 parent e0c6913 commit 0c76613
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 1 deletion.
Binary file modified docs/detections/images/all-rules.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/monitor-table.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
4 changes: 3 additions & 1 deletion docs/detections/rules-ui-manage.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ To filter the rules list, enter a search term in the search bar and press **Retu

NOTE: Searches for index patterns and MITRE ATT&CK tactics and techniques must match exactly, are case sensitive, and do _not_ support wildcards. For example, to find rules using the `filebeat-*` index pattern, the search term `filebeat-*` is valid, but `filebeat` and `file*` are not because they don't exactly match the index pattern. Likewise, the MITRE ATT&CK tactic `Defense Evasion` is valid, but `Defense`, `defense evasion`, and `Defense*` are not.

You can also filter the rules list by selecting the *Tags*, *Elastic rules*, *Custom rules*, *Enabled rules*, and *Disabled rules* filters next to the search bar.
You can also filter the rules list by selecting the *Tags*, *Last response*, *Elastic rules*, *Custom rules*, *Enabled rules*, and *Disabled rules* filters next to the search bar.

The rules list retains your sorting and filtering settings when you navigate away and return to the page. These settings are also preserved when you copy the page's URL and paste into another browser. Select *Clear filters* above the table to revert to the default view.

Expand All @@ -51,6 +51,8 @@ The *Last response* column displays the current status of each rule, based on th

For {ml} rules, an indicator icon (image:images/rules-table-error-icon.png[Error icon from Rules table,15,15]) also appears in this column if a required {ml} job isn't running. Click the icon to list the affected jobs, then click *Visit rule details page to investigate* to open the rule's details page, where you can start the {ml} job.

You can filter rules by status using the *Last response* filter.

[float]
[[load-prebuilt-rules]]
=== Load and activate Elastic prebuilt rules
Expand Down

0 comments on commit 0c76613

Please sign in to comment.