-
Notifications
You must be signed in to change notification settings - Fork 159
Add ESQL for security section, threat hunt tutorial #1689
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🔍 Preview links for changed docs:
🔔 The preview site may take up to 3 minutes to finish building. These links will become live once it completes. |
This was not correct This reverts commit 1c311b3.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left some minor comments, otherwise LGTM!
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
|
||
### Create core indices | ||
|
||
First, create the core security indices for our threat hunting scenario: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Would it be helpful to add an API Reference link to the APIs that are used here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Normally I'm game for richly linking but here this might be an unnecessary ejector seat TBH, but I could be convinced otherwise :)
Ideally we'd have a file upload friendly option for the data-loading TBH and we might revisit this going forward. In meantime API calls are the most lightweight option.
solutions/security/esql-for-security/esql-threat-hunting-tutorial.md
Outdated
Show resolved
Hide resolved
Co-authored-by: natasha-moore-elastic <[email protected]>
URL preview