Skip to content

[ESS][8.18] Editing, exporting, and importing prebuilt rules #6563

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 29 commits into from
Mar 24, 2025

Conversation

nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Mar 3, 2025

Description

Partially addresses #5061 by providing docs for editing, exporting, and importing prebuilt rules (customized and non-customized). Docs for updating customized prebuilt rules are at #6568.

Twin 9.0 and Serverless PR: elastic/docs-content#893

Previews

  • Modify existing rules settings: Made a few changes to this section:
    • Added requirements to the start of the section to explain subscription needs.
    • Updated instructions for editing single rules
  • Export and import rules: Made the following changes:
    • Added requirements to the start of the section to explain subscription needs for importing and exporting custom and prebuilt rules.
    • Split up the instructions for importing and exporting rules to make the content more findable and readable
    • Added instructions for exporting individual rules

@nastasha-solomon nastasha-solomon added Team: Detection Engine Priority: High Issues that are time-sensitive and/or are of high customer importance Effort: Medium Issues that take moderate but not substantial time to complete Docset: ESS Issues that apply to docs in the Stack release v8.18.0 labels Mar 3, 2025
@nastasha-solomon nastasha-solomon self-assigned this Mar 3, 2025
Copy link

github-actions bot commented Mar 3, 2025

A documentation preview will be available soon.

Request a new doc build by commenting
  • Rebuild this PR: run docs-build
  • Rebuild this PR and all Elastic docs: run docs-build rebuild

run docs-build is much faster than run docs-build rebuild. A rebuild should only be needed in rare situations.

If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here.

@nastasha-solomon nastasha-solomon marked this pull request as ready for review March 5, 2025 22:18
@nastasha-solomon nastasha-solomon requested a review from a team as a code owner March 5, 2025 22:18
@banderror banderror requested review from xcrzx and maximpn March 6, 2025 09:25
Copy link
Contributor

@approksiu approksiu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No comments outside of the need to mention licensing. Thanks Nastasha!

@xcrzx xcrzx removed their request for review March 14, 2025 13:40
Copy link
Contributor

@approksiu approksiu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks @nastasha-solomon !

Copy link
Contributor

@banderror banderror left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nastasha-solomon Thank you, a few suggestions and comments that I think we should address in this PR.

Copy link
Contributor

@banderror banderror left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @nastasha-solomon, LGTM 👍

Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work!

@nastasha-solomon nastasha-solomon merged commit ed51c36 into 8.x Mar 24, 2025
4 checks passed
mergify bot pushed a commit that referenced this pull request Mar 24, 2025
* First draft

* Defined missing bulk actions

* Formatting and org fixes

* Minor change to tip about modified prebuilt rules

* possession!

* Incorporate feedback from first round of reviews.

* Cleanup

* Adds note about imported rules without base verions

* Merge branch 'issue-5061-import-export-modify' of github.com:elastic/security-docs into issue-5061-import-export-modify

* Edits

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

Co-authored-by: Georgii Gorbachev <[email protected]>

* Georgii's feedback pt.1

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

---------

Co-authored-by: Georgii Gorbachev <[email protected]>
(cherry picked from commit ed51c36)
nastasha-solomon added a commit to elastic/docs-content that referenced this pull request Mar 24, 2025
nastasha-solomon added a commit that referenced this pull request Mar 24, 2025
…6660)

* First draft

* Defined missing bulk actions

* Formatting and org fixes

* Minor change to tip about modified prebuilt rules

* possession!

* Incorporate feedback from first round of reviews.

* Cleanup

* Adds note about imported rules without base verions

* Merge branch 'issue-5061-import-export-modify' of github.com:elastic/security-docs into issue-5061-import-export-modify

* Edits

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

Co-authored-by: Georgii Gorbachev <[email protected]>

* Georgii's feedback pt.1

* Update docs/detections/rules-ui-manage.asciidoc

* Update docs/detections/rules-ui-manage.asciidoc

---------

Co-authored-by: Georgii Gorbachev <[email protected]>
(cherry picked from commit ed51c36)

Co-authored-by: Nastasha Solomon <[email protected]>
@nastasha-solomon nastasha-solomon deleted the issue-5061-import-export-modify branch March 24, 2025 18:16
@nastasha-solomon nastasha-solomon mentioned this pull request Apr 2, 2025
25 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Effort: Medium Issues that take moderate but not substantial time to complete Priority: High Issues that are time-sensitive and/or are of high customer importance Team: Detections/Response Detections and Response v8.18.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants