[Request] Risk Score calculation for "closed" alerts #6254
Labels
Docset: ESS
Issues that apply to docs in the Stack release
Docset: Serverless
Issues for Serverless Security
Effort: Small
Issues that can be resolved quickly
Feature: Entity Analytics
Features or enhancements for any of the Entity pages
Priority: Medium
Issues that have relevance, but aren't urgent
Team: Entity Analytics
v8.18.0
Description
We are introducing a new feature that allows users to include "closed" alerts in risk score calculations. This enhancement improves the user experience by providing a more comprehensive view of the system.
Users can toggle a button to include closed alerts in the risk score calculation and specify a date/time range for the calculation. Additionally, they can preview the data before finalising and saving these changes for the next engine run.
Background & resources
Test environments:
Kibana: https://kibana-pr-201909-security-f6e262.kb.eu-west-1.aws.qa.elastic.cloud/#
Elasticsearch: https://kibana-pr-201909-security-f6e262.es.eu-west-1.aws.qa.elastic.cloud/
Credentials:
vault read -address=https://secrets.elastic.co:8200 secret/kibana-issues/dev/cloud-deploy/kibana-pr-201909-security
Kibana image: docker.elastic.co/kibana-ci/kibana-serverless:pr-201909-d0f22970266f
Which documentation set does this change impact?
ESS and serverless
ESS release
8.18
Serverless release
Next release
Feature differences
The feature is identical in ESS and serverless
API docs impact
New API endpoint : api/risk_score/engine/saved_object/configure
User can send a
PUT
request to this endpoint to use the feature to include closed alerts for risk score calculationUser can send below information with the request :
For example :
Prerequisites, privileges, feature flags
No response
The text was updated successfully, but these errors were encountered: