Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SIEM][Detections] Create Enable Rule onboarding flow #65943

Closed
spong opened this issue May 9, 2020 · 3 comments
Closed

[SIEM][Detections] Create Enable Rule onboarding flow #65943

spong opened this issue May 9, 2020 · 3 comments
Labels
enhancement New value added to drive a business result Feature:Detection Rules Anything related to Security Solution's Detection Rules Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@spong
Copy link
Member

spong commented May 9, 2020

As part of #65942, two new pre-packaged rules will be introduced to ensure any alert can be used within an investigation. Since it is most beneficial to the user if these rules are enabled right after they're installed, this issue is for displaying a brief onboarding flow after the pre-packaged rules have been installed.

@spong spong added enhancement New value added to drive a business result Team:SIEM v7.9.0 Feature:Detection Rules Anything related to Security Solution's Detection Rules labels May 9, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@spong spong changed the title [SIEM][Detections] Create Enable Alert onboarding flow [SIEM][Detections] Create Enable Rule onboarding flow May 9, 2020
@dontcallmesherryli
Copy link

dontcallmesherryli commented Jul 6, 2020

Per discussion with @MikePaquette and @mchopda this ticket scoped out of 7.9 release. Users will still have pre-built Endpoint Rule default on, but does not see an onboarding flow in the UI. They may see and turn them on/off in the Rules Management page.

@peluja1012
Copy link
Contributor

Closing as we are tracking on-boarding improvements for enabling Elastic Endpoint rules here https://github.com/elastic/security-team/issues/203

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Detection Rules Anything related to Security Solution's Detection Rules Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

5 participants