Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Add support for editing prebuilt rules to the Rule Management and Rule Details pages #180171

Closed
8 tasks
Tracked by #174168
jpdjere opened this issue Apr 5, 2024 · 4 comments · Fixed by #198202
Closed
8 tasks
Tracked by #174168
Assignees
Labels
8.17 candidate Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@jpdjere
Copy link
Contributor

jpdjere commented Apr 5, 2024

Epics: https://github.com/elastic/security-team/issues/1974 (internal), #174168
Design Discussion context: #178211
Design: Figma

Summary

  • Add support for editing prebuilt rules to the Rule Management and Rule Details pages.
  • Single and bulk actions should work for prebuilt rules, such as editing, bulk editing, and exporting.

Acceptance criteria

  • Feature is hidden behind prebuiltRulesCustomizationEnabled feature flag
  • Bulk actions are able to performed on all rule types
    • Editing
      • Index patterns
      • Tags
      • Highlighted fields
      • Schedule
    • Export
@jpdjere jpdjere added triage_needed Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area labels Apr 5, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-rule-management (Team:Detection Rule Management)

@banderror banderror changed the title [Security Solution] Add support for editing prebuilt rules to the Rule Management and Rule Details pages [Security Solution] Add support for editing prebuilt rules to the Rule Management and Rule Details pages (DRAFT) Apr 17, 2024
@dplumlee dplumlee self-assigned this Sep 19, 2024
@dplumlee dplumlee changed the title [Security Solution] Add support for editing prebuilt rules to the Rule Management and Rule Details pages (DRAFT) [Security Solution] Add support for editing prebuilt rules to the Rule Management and Rule Details pages Sep 25, 2024
@banderror
Copy link
Contributor

Thanks @dplumlee for updating the description, LGTM /cc @jpdjere @approksiu

kibanamachine pushed a commit to kibanamachine/kibana that referenced this issue Nov 13, 2024
…the Rule Management and Rule Details pages (elastic#198202)

**Resolves: elastic#180171
**Resolves: elastic#180176
**Resolves: elastic#180173

## Summary

> [!NOTE]
> Feature is behind the `prebuiltRulesCustomizationEnabled` feature
flag.

Adds logic to allow users to edit and export prebuilt rules from both
the Rule management page and Rule details page via the bulk action menu
and the singular overflow menu

### Acceptance criteria

- [x] Feature is hidden behind prebuiltRulesCustomizationEnabled feature
flag
- [x] Modified components still work as expected when feature flag is
off
- [x] Bulk actions are able to performed on all rule types from Rule
management page bulk actions menu
  - [x] Editing
    - [x] Index patterns
    - [x] Tags
    - [x] Highlighted fields
    - [x] Schedule
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule management page overflow column
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule details page
  - [x] Export

### Screenshots
***

### Rule management table overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 38
12 PM](https://github.com/user-attachments/assets/13f8cd87-a9e5-486c-ab0f-d206de8bab4b)

#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
27 PM](https://github.com/user-attachments/assets/4b3d9364-02d5-406a-9f8a-c9ad8fed8486)

### Rule details page overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 37
40 PM](https://github.com/user-attachments/assets/621b56e3-1f47-49db-aedb-fd05a3b75007)

#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
38 PM](https://github.com/user-attachments/assets/d533f288-4393-4acf-ba88-91c32ab32955)

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
(cherry picked from commit 02e4edc)
CAWilson94 pushed a commit to CAWilson94/kibana that referenced this issue Nov 18, 2024
…the Rule Management and Rule Details pages (elastic#198202)

**Resolves: elastic#180171
**Resolves: elastic#180176
**Resolves: elastic#180173

## Summary

> [!NOTE]  
> Feature is behind the `prebuiltRulesCustomizationEnabled` feature
flag.

Adds logic to allow users to edit and export prebuilt rules from both
the Rule management page and Rule details page via the bulk action menu
and the singular overflow menu


### Acceptance criteria

- [x] Feature is hidden behind prebuiltRulesCustomizationEnabled feature
flag
- [x] Modified components still work as expected when feature flag is
off
- [x] Bulk actions are able to performed on all rule types from Rule
management page bulk actions menu
  - [x] Editing
    - [x] Index patterns
    - [x] Tags
    - [x] Highlighted fields
    - [x] Schedule
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule management page overflow column
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule details page
  - [x] Export
 

### Screenshots
***

### Rule management table overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 38
12 PM](https://github.com/user-attachments/assets/13f8cd87-a9e5-486c-ab0f-d206de8bab4b)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
27 PM](https://github.com/user-attachments/assets/4b3d9364-02d5-406a-9f8a-c9ad8fed8486)

### Rule details page overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 37
40 PM](https://github.com/user-attachments/assets/621b56e3-1f47-49db-aedb-fd05a3b75007)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
38 PM](https://github.com/user-attachments/assets/d533f288-4393-4acf-ba88-91c32ab32955)

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
CAWilson94 pushed a commit to CAWilson94/kibana that referenced this issue Nov 18, 2024
…the Rule Management and Rule Details pages (elastic#198202)

**Resolves: elastic#180171
**Resolves: elastic#180176
**Resolves: elastic#180173

## Summary

> [!NOTE]  
> Feature is behind the `prebuiltRulesCustomizationEnabled` feature
flag.

Adds logic to allow users to edit and export prebuilt rules from both
the Rule management page and Rule details page via the bulk action menu
and the singular overflow menu


### Acceptance criteria

- [x] Feature is hidden behind prebuiltRulesCustomizationEnabled feature
flag
- [x] Modified components still work as expected when feature flag is
off
- [x] Bulk actions are able to performed on all rule types from Rule
management page bulk actions menu
  - [x] Editing
    - [x] Index patterns
    - [x] Tags
    - [x] Highlighted fields
    - [x] Schedule
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule management page overflow column
  - [x] Export
- [x] Singular rule actions are able to be performed on all rule types
from rule details page
  - [x] Export
 

### Screenshots
***

### Rule management table overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 38
12 PM](https://github.com/user-attachments/assets/13f8cd87-a9e5-486c-ab0f-d206de8bab4b)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
27 PM](https://github.com/user-attachments/assets/4b3d9364-02d5-406a-9f8a-c9ad8fed8486)

### Rule details page overflow menu

#### Before
**Export button is disabled for prebuilt rules**
![Screenshot 2024-11-07 at 7 37
40 PM](https://github.com/user-attachments/assets/621b56e3-1f47-49db-aedb-fd05a3b75007)


#### After
**Export button is enabled for all rule types**
![Screenshot 2024-11-07 at 7 34
38 PM](https://github.com/user-attachments/assets/d533f288-4393-4acf-ba88-91c32ab32955)

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
8.17 candidate Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
4 participants