elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.59k stars 8.1k forks source link

Indicator Match rule apply exception also for threat index #151469

Open nkhristinin opened 1 year ago

nkhristinin commented 1 year ago

Make it more clear that the Indicator Match rule apply exception also for the threat index

Currently, when you create an exception in the Indicator Match rule, it applies both to the source index and threat index.

This behaviour can be not so clear for the user. We probably have several options here

  1. Keep it as it is and add some UI text that exceptions apply for both indices.
  2. Separate default rule exceptions and create different type for threat indices exception
elasticmachine commented 1 year ago

Pinging @elastic/security-detections-response (Team:Detections and Resp)