elastic / elastic/detection-rules

[FR] CI Job to Sync ES|QL Custom Fields with Prebuilt Filterlist for Telemetry

Open
#4,168 3 comments 0 reactions 0 assignees View on GitHub
backlog enhancement Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

### Repository Feature

Core Repo - (rule management, validation, testing, lib, cicd, etc.)

### Problem Description

At the moment, when using ES|QL for writing detection rule queries, often we use aggregate functions, eval or pre-processing functions (grok and dissect) to create useful fields for our filters.

In this instance, those fields are not available in global alert telemetry, which relies on a static filterlist for determining what fields to ingest from the alerts.

### Desired Solution

As such, we must develop a CI job that loads the ES|QL rules, reviews custom fields and adds those to the filterlist. The CI job would run on merges into main only.

### Considered Alternatives

No alternatives considered. This suggestion is post conversation with Security Data Analytics team.

### Additional Context

Related to https://github.com/elastic/ia-trade-team/issues/101

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.