-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
[Serverless][8.18] EQL Sequence alert suppression #6291
Conversation
A documentation preview will be available soon. Request a new doc build by commenting
If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here. |
Per this comment, this feature didn't make it into 8.17. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just one clarification. Looks great!
…stic/security-docs into issue-5886-alert-suppression-eql-seq
50f54a4
* First draft * draft 1 * Update docs/detections/alert-suppression.asciidoc * fix it? * Moves info * updating ref * Update docs/detections/building-block-rule.asciidoc * Update docs/serverless/rules/building-block-rule.asciidoc * Removing empty lines * Removes tech preview label for 8.18 * updates note about reqs * Re-adds + * Fixes Serverless note * Fixes numebring (cherry picked from commit ed389ce) # Conflicts: # docs/serverless/alerts/alert-suppression.asciidoc
…) (#6381) * [Serverless][8.18] EQL Sequence alert suppression (#6291) * First draft * draft 1 * Update docs/detections/alert-suppression.asciidoc * fix it? * Moves info * updating ref * Update docs/detections/building-block-rule.asciidoc * Update docs/serverless/rules/building-block-rule.asciidoc * Removing empty lines * Removes tech preview label for 8.18 * updates note about reqs * Re-adds + * Fixes Serverless note * Fixes numebring (cherry picked from commit ed389ce) # Conflicts: # docs/serverless/alerts/alert-suppression.asciidoc * Delete docs/serverless directory and its contents --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Fixes #5886
ESS
Serverless
NOTE: Suppression for EQL rules in Serverless will go GA around the same time that 8.18 GAs. I'll open a separate PR to update the Serverless docs once that date approaches.