elastic / elastic/integrations

[Data Exfiltration Detection] Anomaly Explorer shows events in the timeline that fit the description but no Alerts are created in the respective Detection Rule

Open
#14,979 9 comments 0 reactions 1 assignee Claimed by @sodhikirti07 View on GitHub
Integration:ded needs:triage Stalled Team:Security-Applied ML
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 18h
Merged PRs (30d)
182

Description

### Integration Name

Data Exfiltration Detection [ded]

### Dataset Name

_No response_

### Integration Version

2.3.3

### Agent Version

8.14.3

### Agent Output Type

elasticsearch

### Elasticsearch Version

8.14.3

### OS Version and Architecture

Linux

### Software/API Version

_No response_

### Error Message

_No response_

### Event Original

_No response_

### What did you do?

Installed the Data Exfiltration Detection Integration and follwed the installation guide.
Also noteworthy: Added the logs-endpoint.events.network-* index to the Data View that got clarified in a previous Issue https://github.com/elastic/integrations/issues/14677 and updated documentation in 2.3.4.

### What did you see?

Activated Anomaly Detection Jobs:
- ded_high_sent_bytes_destination_ip
- ded_high_sent_bytes_destination_port

The Anomaly Explorer does show events:
Image

Following that are only the related Detection Rules active:
- Potential Data Exfiltration Activity to an Unusual IP Address
- Potential Data Exfiltration Activity to an Unusual Destination Port

The Detection Rules are running and succeed in their iterations.

### What did you expect to see?

While there are events in the Anomaly Explorer, even with a Severity of 99 and less, there are no Alerts created from the Detection Rule Potential Data Exfiltration Activity to an Unusual Destination Port.

The Detection Rule Potential Data Exfiltration Activity to an Unusual IP Address creates Alerts, although not that many- even though the Anomaly Explorer shows similar events like shown in the screen shot of the Anomaly Explorer above with lots of events that fit the description of more than 100x higher.
The Alerts listed are indeed events with an actual number of over 100x than typical.

Image

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.