Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[New Rule] Elastic Endpoint and External Alerts #41

Closed
spong opened this issue Jul 8, 2020 · 0 comments · Fixed by #42
Closed

[New Rule] Elastic Endpoint and External Alerts #41

spong opened this issue Jul 8, 2020 · 0 comments · Fixed by #42
Labels

Comments

@spong
Copy link
Member

spong commented Jul 8, 2020

Description

In support of elastic/kibana#65942 to create two new pre-packaged rules that will enable Elastic Endpoint Alerts and External Alerts to be used in investigations.

Required Info

  • Eventing Sources: Elastic Endpoint and all external sources where event.kind:alert
  • Target Operating Systems: All
  • Platforms: All
  • Target ECS Version: 1.5.0
  • New fields required in ECS for this? Associated issue/PR: n/a

Optional Info

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants