elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.69k stars 8.11k forks source link

[Defend Workflow][Question]How to generate Data to test Analyzer for Sentinelone alert. #177812

Closed sukhwindersingh-qasource closed 6 months ago

sukhwindersingh-qasource commented 6 months ago

Describe the bug: [Question]How to generate Data to test Analyzer for Sentinelone alert.

Build Details:

VERSION: 8.13.0 BC2
BUILD: 71815
COMMIT: c2fc8da128504d437897970d142efd4d06970c0b

Preconditions

Steps to Reproduce

Screen-Cast

https://github.com/elastic/kibana/assets/108654988/0d12ad20-de4c-4eca-9fe0-237da3cf7c85

Query

elasticmachine commented 6 months ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 6 months ago

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

muskangulati-qasource commented 6 months ago

Reviewed and assigned to @dasansol92

dasansol92 commented 6 months ago

@tomsonpl could you help on these queries? Thanks!

tomsonpl commented 6 months ago

@sukhwindersingh-qasource hey, I haven't specified any strict query... but some tips that can help you are:

Hope this helps, feel free to reach out to me, we can try doing it together 👍

sukhwindersingh-qasource commented 6 months ago

Hi @tomsonpl, Thank you for your assistance. As we discussed on Slack, changes were made to the SentinelOne Cloud Funnel. The bucket name was updated to - name: sentinel_one. Following these changes, we are now able to test the analyzer for SentinelOne alerts.

Below are the observations :

https://github.com/elastic/kibana/assets/108654988/ddca536c-f115-46bb-99c4-f4a48d9a5d94

Hence we are closing this ticket. Thanks !