Pre-built rule / content packs in the New Kibana Alerting Experience
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**What the feature is (as Title)**
Pre-built rules and content packs in the New Kibana Alerting Experience
**Value proposition**
Standing up meaningful alerting coverage takes time: teams must learn ES|QL, decide which signals matter, tune thresholds, and wire notification policies often while critical services already run in production with gaps. Many organizations either under-monitor (missing incidents) or over-page (noisy custom rules built without a consistent baseline). The New Kibana Alerting Experience will ship curated pre-built rules and content packs—ready-to-enable monitoring coverage for common observability, infrastructure, and security scenarios. Instead of authoring every rule from scratch, users can install Elastic-maintained packs from a rule library, review what each rule detects, and enable them.
**Expected outcome**
Teams move from “we have data in Elastic” to “we have actionable monitoring” in hours instead of weeks, without every engineer becoming an alerting expert first. Pre-built rules and content packs embed Elastic’s recommended detections into the New Kibana Alerting Experience so teams start from proven coverage instead of a blank slate. Packs group related rules by use case: integrations, platform health, application signals, and more. Users can adopt monitoring in coherent bundles. Starting in detection mode gives wide visibility without immediate notification risk; switching individual rules to alert mode lets teams promote only the signals that match their environment and on-call tolerance.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.