-
Notifications
You must be signed in to change notification settings - Fork 191
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add new terms rule type to Detections API create/update rule docs #3914
Conversation
Documentation previews: |
This pull request does not have a backport label. Could you fix it @marshallmain? 🙏
NOTE: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for raising the PR, @marshallmain! LGTM, just a couple of suggestions:
- Can we add the following text to the list of rule types at the start of the
rules-api-create
page (on line 36, after Machine learning rules):
New terms: Generates an alert for each new term detected in source documents within a specified time range.
- Can we add request and response examples for creating a new terms rule to the
rules-api-create
page? Just to keep the consistency, as the page contains examples for all other rule types.
Thanks for the heads-up – once we merge this PR, I can raise a separate one to update the description to |
Co-authored-by: natasha-moore-elastic <[email protected]>
Hey @marshallmain, just flagging these two points again in case you missed them. |
Co-authored-by: natasha-moore-elastic <[email protected]>
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155)
) (#3975) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
) (#3976) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
) (#3977) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
) (#3978) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
) (#3979) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
) (#3980) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
) (#3981) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit cbd0155) Co-authored-by: Marshall Main <[email protected]>
* Add alert suppression clarification note Per /pull/3879 * Clarify note in new terms rule create Per /pull/3943 * Update images for QA bugs Per /pull/3946 * Add new terms rule type to create rule API docs Per /pull/3914 * Add new terms rule type to *update* rule API docs Per /pull/3914
) (#3978) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit 67448e0) Co-authored-by: Marshall Main <[email protected]>
) (#3979) * Add new terms rule type to Detections API create/update rule docs * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Update copy for history_window_start recommended format * Apply suggestions from code review Co-authored-by: natasha-moore-elastic <[email protected]> * Add example request and response for new terms rule * Fix copy paste errors --------- Co-authored-by: natasha-moore-elastic <[email protected]> (cherry picked from commit 67448e0) Co-authored-by: Marshall Main <[email protected]>
Adds API docs for the new terms rule type, introduced in elastic/kibana#134526 (stack v8.4.0). Support for multiple values in
new_terms_fields
was added in 8.6 (elastic/kibana#143943), so if we backport as far as 8.4 and 8.5 we should modify theMust contain 1-3 field names.
text to reflect the limitation (something likeMust contain 1 field name.
instead).