Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Detections] Provide ability to deep link into Detection views #92345

Open
spong opened this issue Feb 23, 2021 · 3 comments
Labels
enhancement New value added to drive a business result Feature:Rule Exceptions Security Solution Rule Exceptions feature Feature:Rule Management Security Solution Detection Rule Management Team:Detection Engine Security Solution Detection Engine Area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@spong
Copy link
Member

spong commented Feb 23, 2021

This enhancement is for providing the ability to deep link to specific views within the detection engine, exposing query parameters that allows users to create custom URL's within their actions (or elsewhere) to link to specific pages/views within Detections.

Below are example deep-linking parameters per page.

Main Detections Page
  • stack by field on histogram
  • alert status filter
  • include building blocks additional filter on table
  • alerts per page on table
  • sort_column on table
  • current_page on table

Note: KQL Query/Filters and Daterange are already available on the main detections page.

Rule Management Page
  • Selected tab (Rules, Rule Monitoring, Exception Lists)
  • Per each tab
    • query string
    • Elastic Rule/Custom Rule filters
    • Selected tags
    • Sort order
    • Current page on table
    • Rules per page on table
  • Show Upload value lists modal on page load
  • Show Import rule modal on page load
Rule Details Page
  • Selected tab (Detection Alerts, Exception, Failure History)
  • Selected tab within About section (either Details or Investigation guide)
  • All parameters outlined in Main Detection Page section above
  • Exceptions Table
    • query string
    • Detection list/Endpoint list filters
  • Show Add Endpoint Exception modal
  • Show Add Rule Exception modal
Create Rule Page
  • Selected Rule Type (Custom Query, Machine Learning, Threshold, Event Correlation, Indicator Match)
Edit Rule Page
  • Selected Tab (Definition, About, Schedule, Actions)
@spong spong added enhancement New value added to drive a business result Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Feature:Rule Exceptions Security Solution Rule Exceptions feature Feature:Rule Management Security Solution Detection Rule Management labels Feb 23, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@approksiu
Copy link

@spong I would add for "Rule Details Page" the investigation guide section.

@banderror banderror added the Team:Detection Rule Management Security Detection Rule Management Team label Apr 27, 2022
@yctercero yctercero added Team:Detection Engine Security Solution Detection Engine Area and removed Team:Security Solution Platform Security Solution Platform Team labels May 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Rule Exceptions Security Solution Rule Exceptions feature Feature:Rule Management Security Solution Detection Rule Management Team:Detection Engine Security Solution Detection Engine Area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

5 participants