Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SIEM] Removes prebuilt rules number dependency #65128

Merged
merged 5 commits into from
May 5, 2020

Conversation

MadameSheema
Copy link
Member

Summary

In this PR we are removing the number of prebuilt rules dependency.

Now we are getting the number of expected prebuilt rules from the rawRules array located in x-pack/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/index.ts. In this way we don't need to updated the test every time that we add or remove a new prebuilt rule.

@MadameSheema MadameSheema added Team:SIEM v8.0.0 release_note:skip Skip the PR/issue when compiling release notes v7.8.0 labels May 4, 2020
@MadameSheema MadameSheema requested review from a team as code owners May 4, 2020 17:50
@MadameSheema MadameSheema self-assigned this May 4, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@MadameSheema MadameSheema requested a review from dhurley14 May 4, 2020 17:51
Copy link
Contributor

@rylnd rylnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are some CI failures so I'm just adding comments, for now.

x-pack/plugins/siem/cypress/objects/rule.ts Outdated Show resolved Hide resolved
x-pack/plugins/siem/cypress/objects/rule.ts Outdated Show resolved Hide resolved
@MadameSheema MadameSheema force-pushed the removes-rules-dependency branch from e9afee0 to 8f8c04f Compare May 5, 2020 08:39
@MadameSheema MadameSheema force-pushed the removes-rules-dependency branch from 8f8c04f to 32cf919 Compare May 5, 2020 11:12
@kibanamachine
Copy link
Contributor

💚 Build Succeeded

History

  • 💔 Build #45423 failed 8f8c04f180dda3b94677f5d060e930e7661a83d6
  • 💔 Build #45202 failed e9afee0ec52dbc50cbe56daf58847b74ceb42f63
  • 💔 Build #45161 failed 4936ed9666a50664f7e445151719c64b6156e5c2

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

Copy link
Member

@spong spong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me! 👍 Thanks for unraveling these dependencies and helping improve the rule update flow for the @elastic/security-intelligence-analytics folks @MadameSheema! 🙂

@MadameSheema MadameSheema merged commit 33b3c7b into elastic:master May 5, 2020
@MadameSheema MadameSheema deleted the removes-rules-dependency branch May 5, 2020 14:41
MadameSheema added a commit to MadameSheema/kibana that referenced this pull request May 5, 2020
* removes prebuilt rules number dependency

* fixes type check issue

* improves eslint comment

* improves constant naming

* fixes failures
# Conflicts:
#	x-pack/plugins/siem/cypress/objects/rule.ts
gmmorris added a commit to gmmorris/kibana that referenced this pull request May 5, 2020
* master: (133 commits)
  Cleanup Typescript index pattern field editor / Expression functions for bucket agg (elastic#65254)
  Removes legacy infra plugin and moves saved objects registration to NP (elastic#64848)
  Added support for docLinks plugin in Connectors forms and missing save capabilities for modal dialog (elastic#64986)
  [SIEM] Removes prebuilt rules number dependency (elastic#65128)
  [Maps] add categorical palettes with 20 and 30 categories (elastic#64701)
  [CI] Slack alerts - Elasticsearch snapshot failures (elastic#64724)
  [Uptime] Console errors in case index missing (elastic#65115)
  [SIEM][CASE] Dynamic fields mapping based on connector (elastic#64412)
  [test/functional] Tsfy page objects (elastic#64887)
  [Maps] [Telemetry] Track geo_point and geo_shape index patterns separately (elastic#65195)
  [Maps] Add global fit to data (elastic#64702)
  Visualize: Reload on ui state change and fix ui state for tsvb (elastic#63699)
  [SIEM] [Cases] External service selection per case (elastic#64775)
  [Uptime] Set ML anomaly look-back to 2w (from 24h) / Add spinner (elastic#65055)
  [Metrics UI] Remove APM Hard Dependency (elastic#64952)
  [Ingest] Datastream list: add icons and dashboard links (elastic#65048)
  disable plugins. they could access ES via SO repository (elastic#65242)
  Feature fleet enrollment instructions (elastic#65176)
  [SIEM] Adds 'Configure connector' Cypress test (elastic#64807)
  [TSVB] Fix std deviation band mode (elastic#64413)
  ...
spong added a commit that referenced this pull request May 6, 2020
* removes prebuilt rules number dependency

* fixes type check issue

* improves eslint comment

* improves constant naming

* fixes failures
# Conflicts:
#	x-pack/plugins/siem/cypress/objects/rule.ts

Co-authored-by: Garrett Spong <spong@users.noreply.github.com>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Sep 23, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
release_note:skip Skip the PR/issue when compiling release notes Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM v7.8.0 v8.0.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants