elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.68k stars 8.23k forks source link

Tines Connector is available as a Connector type in Security alert rules but not in Observability alert rules #194895

Open ck-elastic opened 1 month ago

ck-elastic commented 1 month ago

Link to support case or sales opportunity (if relevant): Phase 1: https://elastic.lightning.force.com/lightning/r/Opportunity/0068X00001HNYMQQA5/view Phase 2: https://elastic.lightning.force.com/lightning/r/Opportunity/0068X00001IASzfQAH/view

Link to Github issues (if available): None

Customer Details - Name: OCBC

Customer Details - Products/Versions: Elastic stack 8.12

Customer Details - Workarounds (if any): None

Describe the feature: Customer wants to be able to send their observability alerts to Tines for automated resolution and remediation. As can be seen in attached screenshot, Tines is available as an alert connector type for Security but not Observability.

Observability Rules Connector Type: Image

Security Rules Connector Type: Image

Describe a specific use case for the feature: After setting up Tines, a observability alert, example high CPU, will trigger a Tines workflow to scale up another app node.

elasticmachine commented 1 month ago

Pinging @elastic/response-ops (Team:ResponseOps)

heespi commented 1 month ago

Hi @asnehalb ... this issue came to us but I believe Tines is owned by Security Solutions. Would you be able to help @ck-elastic here or find the right owner, please?

CC: @cnasikas

ck-elastic commented 4 weeks ago

Hi @asnehalb may I have your input for this? This ER is to create a Tines connector for Observability so that Tines can automate the actions to be performed when, for example, an observability alert is triggered.