elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
194 stars 418 forks source link

Replace logs stream panels with saved searches #10516

Open flash1293 opened 1 month ago

flash1293 commented 1 month ago

The logs stream application and embeddables are going to be deprecated and removed in a future version (see https://github.com/elastic/observability-dev/issues/3242).

This means dashboards shouldn't use the logs stream panel type anymore. Instead, they should be replaced by saved searches.

The following dashboards need to be changed:

flash1293 commented 1 month ago

cc @elastic/security-service-integrations @elastic/sec-deployment-and-devices could you take a look please and let me know whether there are any questions?

flash1293 commented 1 month ago

FYI @gbamparop

andrewkroh commented 1 month ago

I think one team can handle the updates to both package despite ownership. Added it to the elastic/sec-deployment-and-devices backlog.

qcorporation commented 1 month ago

@flash1293 is my understanding correct that this needs to be done for 8.16?

flash1293 commented 1 month ago

@qcorporation In 8.16, things will still work, it should be done by 9.0 - the earlier the better of course :)

taylor-swanson commented 1 month ago

As an aside, there's an SDH for log streams in Check Point, although I don't think the issue is with the log stream visualization itself. If there does end up being an issue with the visualization, it will be a good opportunity to migrate to a saved search.