opensearch-project / opensearch-project/security-analytics

[FEATURE] Security Analytics: Inlcude findings as ctx.results

Open
#696 8 comments 5 reactions 1 assignee View on GitHub

@eirsep is already working on this.

Since May 1, 2024.

enhancement
Dominant language
Java
Stars
111
Forks
111
Avg merge
1d 17h
Merged PRs (30d)
13

Description

Is your feature request related to a problem?
ctx.results is present in alerts but always empty. Enriching detector alerts with details from findings is not possible.

What solution would you like?
In Alerting ctx.results is populated and can be used. Including findings as ctx.results in Security Analytics would be consistent with the behaviour in Alerting. Also, including details from the findings via ctx.results in the trigger message would greatly improve alerting workflows.

What alternatives have you considered?
I do not see an alternative, since the information is currently just not available.

Do you have any additional context?
I am referring to the feature set of OpenSearch 2.10 using notification messages in alert trigger in the Security Analytics plugin.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.