-
Notifications
You must be signed in to change notification settings - Fork 191
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[DOCS][Rules][Data Views] - Data views available in rule creation flow #1832
Comments
related PR: elastic/kibana#130929 |
Some screenshots please let me know if you need more! cc @joepeeples |
@dhurley14 when you're ready, feel free to reach out to the @elastic/security-docs team for help crafting and reviewing the UI tour text for this feature. |
Error state when imported rule where data view does not exist - elastic/kibana#137841 |
Reassigning to @jmikell821 since she's documenting rule creation for 8.4 in #2258. |
Hey there! We'd discussed needing additional details for documenting. Hopefully the following helps: API changes
Affected flowsRule Creation
Rule Edit
Rule Details
Rules Management
Add/edit rule exception modal
|
Description
Users can specify data views wherever index pattern specification is available in order to take advantage of runtime fields, which are associated with a data view.
Issue: https://github.com/elastic/security-team/issues/2874
PR: elastic/kibana#130929
Acceptance Test Criteria
rule name override
.group by
field, if they configured a Data View as the data source.Indicator mapping field
andIndicator index field
configurations..alerts
Data View so they can take advantage of any runtime fields they may have added.Notes
The text was updated successfully, but these errors were encountered: