Update Entity related rules with new _ea ML job ID and update minimum stack versions#5794
Update Entity related rules with new _ea ML job ID and update minimum stack versions#5794susan-shu-c wants to merge 12 commits intomainfrom
_ea ML job ID and update minimum stack versions#5794Conversation
|
⛔️ Test failed Results
|
Rule: Tuning - GuidelinesThese guidelines serve as a reminder set of considerations when tuning an existing rule. Documentation and Context
Rule Metadata Checks
Testing and Validation
|
| license = "Elastic License v2" | ||
| machine_learning_job_id = "rare_method_for_a_username" | ||
| machine_learning_job_id = "rare_method_for_a_username_euid" | ||
| name = "Unusual AWS Command for a User" |
There was a problem hiding this comment.
@susan-shu-c Could you confirm the process to update the investigation guide?
There was a problem hiding this comment.
On it, pending response!
There was a problem hiding this comment.
For new rules: there is a process to kick off, we now have permissions
For existing rules: manually edit
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
_ea ML job ID and update minimum stack versions
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
Confirmed that all of 105 ML jobs referenced here match the corresponding branches in Kibana/integrations |
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
I've also added a new rule Commit with the new rule: 13179fd I based the new rule off these two existing/similar rules, but requesting review: rules/ml/execution_ml_windows_anomalous_script.toml
rules/ml/persistence_ml_rare_process_by_host_windows.toml
|
Pull Request
Issue link(s):
Summary - What I changed
Corresponds with changes to ML jobs in
This PR will:
_easuffixHow To Test
Checklist
bug,enhancement,schema,maintenance,Rule: New,Rule: Deprecation,Rule: Tuning,Hunt: New, orHunt: Tuningso guidelines can be generatedmeta:rapid-mergelabel if planning to merge within 24 hoursContributor checklist