elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.76k stars 8.17k forks source link

[Security Solution] Implement array of scalar values diff algorithm #180162

Closed jpdjere closed 2 months ago

jpdjere commented 6 months ago

Epics: https://github.com/elastic/security-team/issues/1974 (internal), https://github.com/elastic/kibana/issues/174168

Summary

Implement an algorithm for diffing and merging changes in array of scalar values type of fields of detection rules.

Context from the Rule Customization RFC:

To do

elasticmachine commented 6 months ago

Pinging @elastic/security-detections-response (Team:Detections and Resp)

elasticmachine commented 6 months ago

Pinging @elastic/security-detection-rule-management (Team:Detection Rule Management)

elasticmachine commented 6 months ago

Pinging @elastic/security-solution (Team: SecuritySolution)

dplumlee commented 3 months ago

Here are the proposed fields that would utilize this diff algorithm:

Common fields

Threat match fields

New terms fields

dplumlee commented 2 months ago

Resolved by: