elastic / elastic/integrations
[Data Exfiltration Detection] Anomaly Explorer shows events in the timeline that fit the description but no Alerts are created in the respective Detection Rule
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 182
Description
### Integration Name
Data Exfiltration Detection [ded]
### Dataset Name
_No response_
### Integration Version
2.3.3
### Agent Version
8.14.3
### Agent Output Type
elasticsearch
### Elasticsearch Version
8.14.3
### OS Version and Architecture
Linux
### Software/API Version
_No response_
### Error Message
_No response_
### Event Original
_No response_
### What did you do?
Installed the Data Exfiltration Detection Integration and follwed the installation guide.
Also noteworthy: Added the logs-endpoint.events.network-* index to the Data View that got clarified in a previous Issue https://github.com/elastic/integrations/issues/14677 and updated documentation in 2.3.4.
### What did you see?
Activated Anomaly Detection Jobs:
- ded_high_sent_bytes_destination_ip
- ded_high_sent_bytes_destination_port
The Anomaly Explorer does show events:
Following that are only the related Detection Rules active:
- Potential Data Exfiltration Activity to an Unusual IP Address
- Potential Data Exfiltration Activity to an Unusual Destination Port
The Detection Rules are running and succeed in their iterations.
### What did you expect to see?
While there are events in the Anomaly Explorer, even with a Severity of 99 and less, there are no Alerts created from the Detection Rule Potential Data Exfiltration Activity to an Unusual Destination Port.
The Detection Rule Potential Data Exfiltration Activity to an Unusual IP Address creates Alerts, although not that many- even though the Anomaly Explorer shows similar events like shown in the screen shot of the Anomaly Explorer above with lots of events that fit the description of more than 100x higher.
The Alerts listed are indeed events with an actual number of over 100x than typical.
### Anything else?
_No response_
Contributor guide
Assessment
This issue has not been assessed yet.