Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Request][Serverless][ESS] EQL Sequence alert suppression #5886

Open
nastasha-solomon opened this issue Oct 4, 2024 · 0 comments
Open

[Request][Serverless][ESS] EQL Sequence alert suppression #5886

nastasha-solomon opened this issue Oct 4, 2024 · 0 comments
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Small Issues that can be resolved quickly Feature: Rules Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine

Comments

@nastasha-solomon
Copy link
Contributor

Description

Alert suppression is now supported for EQL rules using sequence queries.

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

8.16

Serverless release

TBD

Feature differences

N/A

API docs impact

Prerequisites, privileges, feature flags

N/A

@nastasha-solomon nastasha-solomon added Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Small Issues that can be resolved quickly Feature: Rules Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine v8.16.0 labels Oct 4, 2024
@nastasha-solomon nastasha-solomon self-assigned this Oct 4, 2024
@nastasha-solomon nastasha-solomon changed the title [Request][Serverless][8.16] EQL Sequence alert suppression [Request][Serverless][ESS] EQL Sequence alert suppression Oct 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Small Issues that can be resolved quickly Feature: Rules Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detection Engine
Projects
None yet
Development

No branches or pull requests

1 participant