-
Notifications
You must be signed in to change notification settings - Fork 209
[Enhancement]: Improve examples of detection rule exceptions using wildcards #5334
Copy link
Copy link
Open
Labels
Team: Detection EngineenhancementNew feature or requestNew feature or requestsdh-linkedAssociated to SDHAssociated to SDH
Description
Description
Exceptions with wildcards are tricky to implement for users because the users' expectations do not always match up with the result of the exception because of the type of data mapped to the field they want to "except" on. I believe adding clearer and more examples of what will and what will not match with a given wildcard exception would be beneficial for customers and reduce the number of support cases we receive.
Related links / assets
Related SDH's:
https://github.com/elastic/sdh-security-team/issues/981
https://github.com/elastic/sdh-security-team/issues/887
Which documentation set needs improvement?
ESS and serverless
Software version
8.4
Introduced in this PR: elastic/kibana#136147
Collaborators
PM: @approksiu
Designer:
Developer:
Others (if applicable): @yctercero
Timeline / deliverables
I think within the 8.15 release would be preferable.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Team: Detection EngineenhancementNew feature or requestNew feature or requestsdh-linkedAssociated to SDHAssociated to SDH
Type
Fields
Give feedbackNo fields configured for issues without a type.