Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Suggestion] Add example of excluding cold/frozen data from Indicator Match rule queries #5895

Closed
wants to merge 3 commits into from

Conversation

nastasha-solomon
Copy link
Contributor

@nastasha-solomon nastasha-solomon commented Oct 4, 2024

Fixes https://github.com/elastic/security-docs-internal/issues/47 by directing users toward instructions for filtering out cold and frozen documents during the rule execution phase.

Preview: https://security-docs_bk_5895.docs-preview.app.elstc.co/guide/en/security/master/detection-engine-overview.html#support-indicator-rules

@nastasha-solomon nastasha-solomon added Feature: Rules Team: Detection Engine Priority: Medium Issues that have relevance, but aren't urgent Effort: Medium Issues that take moderate but not substantial time to complete v8.16.0 labels Oct 4, 2024
@nastasha-solomon nastasha-solomon self-assigned this Oct 4, 2024
Copy link

github-actions bot commented Oct 4, 2024

A documentation preview will be available soon.

Request a new doc build by commenting
  • Rebuild this PR: run docs-build
  • Rebuild this PR and all Elastic docs: run docs-build rebuild

run docs-build is much faster than run docs-build rebuild. A rebuild should only be needed in rare situations.

If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here.

@nastasha-solomon
Copy link
Contributor Author

Making these changes in #5962 instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Effort: Medium Issues that take moderate but not substantial time to complete Feature: Rules Priority: Medium Issues that have relevance, but aren't urgent Team: Detection Engine v8.16.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant