-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Telemetry: Update host filter list for detection rules #130095
Conversation
Pinging @elastic/security-solution (Team: SecuritySolution) |
💛 Build succeeded, but was flakyTest Failures
Metrics [docs]
To update your PR or re-run it, just comment with: cc @pjhampton |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
💔 All backports failed
Manual backportTo create the backport manually run:
Questions ?Please refer to the Backport tool documentation |
Friendly reminder: Looks like this PR hasn’t been backported yet. |
(cherry picked from commit 9c8440a)
💚 All backports created successfully
Note: Successful backport PRs will be merged automatically after passing CI. Questions ?Please refer to the Backport tool documentation |
Summary
Issue backref'd from a private repo.
Test of this new telemetry found that
host
filterlist was too permissive bringing back IP and Mac addresses. This is a 8.2 feature that has yet to be released. This PR lines up thehost
filterlist with the endpoint alerts.This functionality is already covered with tests in https://github.com/elastic/kibana/blob/3877763e118b9e20b88eb9f89eb083d4581679fc/x-pack/plugins/security_solution/server/lib/telemetry/filterlists/index.test.ts
Checklist
Delete any items that are not applicable to this PR.
Risk Matrix
Delete this section if it is not applicable to this PR.
Before closing this PR, invite QA, stakeholders, and other developers to identify risks that should be tested prior to the change/feature release.
When forming the risk matrix, consider some of the following examples and how they may potentially impact the change:
For maintainers