-
Notifications
You must be signed in to change notification settings - Fork 184
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[8.16] Updates docs for and related to the excludedDataTiersForRuleExecution
advanced setting
#5962
Conversation
A documentation preview will be available soon. Request a new doc build by commenting
If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here. |
excludedDataTiersForRuleExecution
advanced setting
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
With the phrase The best path forward continues to be modifying the index patterns to only use hot tier data.
, are we specifically intending to reference guidance that we've provided before? An alternative might be The best path forward is to modify the index patterns to only use hot tier data.
.
Also @yctercero do we have a specific modification we can provide that works across the board, e.g. -partial*
to exclude frozen indices? Do we know if that would work everywhere? Users might read "just modify your index patterns" and think that's a monumental task unless we have an easy specific change they can make.
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com>
Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left a few minor comments which may or may not be helpful! Lmk when you're ready for an approval
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc
Outdated
Show resolved
Hide resolved
…idoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
…idoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
…idoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com>
…xecution` advanced setting (#5962) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b)
…xecution` advanced setting (#5962) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b)
…orRuleExecution` advanced setting (backport #5962) (#6174) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
…rRuleExecution` advanced setting (backport #5962) (#6173) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit cd4f12b) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
…orRuleExecution` advanced setting (backport #5962) (#6174) * First draft * Updating IM rules * disclaimer about certain rule types and shards * Minor tweak to dsl query docs * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Marshall's suggestion * Update docs/detections/detection-engine-intro.asciidoc * Removes note that's no longer needed * Moves file back to remove this change from the PR * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Updates what's new * Fixed title * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/getting-started/advanced-setting.asciidoc * Update docs/whats-new.asciidoc * Update docs/whats-new.asciidoc * Update docs/release-notes/8.16.asciidoc * Fixes a typo * Minor wording adjustments * Update docs/whats-new.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/release-notes/8.16.asciidoc Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> * Update docs/getting-started/advanced-setting.asciidoc * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detections-exclude-cold-frozen-data-tiers.asciidoc Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> * Update docs/detections/detection-engine-intro.asciidoc Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> --------- Co-authored-by: Marshall Main <55718608+marshallmain@users.noreply.github.com> Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com> Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com> (cherry picked from commit e6d6ec9) Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
Fixes #5925 and https://github.com/elastic/security-docs-internal/issues/47 by updating the explanation for filtering out cold and frozen documents during rule executions and adding the disclaimer about certain rule types and cold/frozen shards.
Previews:
excludedDataTiersForRuleExecution
advanced setting