-
Notifications
You must be signed in to change notification settings - Fork 165
[Security][9.x] Add 'search.allow_expensive_queries' to detections-requirements.md #3543
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🔍 Preview links for changed docs |
|
Ready to review. Thanks! 😁 🙏 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @sdesalas for the important observation and opening this documentation improvement! I left a small suggestion.
Let's defer to @nastasha-solomon for a final review and approval.
1316de5 to
7104b04
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM 🚀
Co-authored-by: Georgii Gorbachev <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Left some suggestions for your consideration and a few questions as well. Thanks!
Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: Nastasha Solomon <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggested changing the numbers to list bullets because these tasks don't need to be completed in a specific order. They just need to be completed in the same file (the elasticsearch.yml file).
Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: Nastasha Solomon <[email protected]>
809c4f9 to
f880825
Compare
32cd1be to
24eac20
Compare
Summary
De-facto requirement of Security Detections, (and much of Kibana) that has not been documented properly.
Errors go as far back as
v8.18(but likely much further), and not only affect Security app, but also manyServer Managementfeatures such as Fleet, Saved Objects, Tags, etc.For more info: elastic/kibana#237496 -> Section
Risks that were found acceptableWe're documenting it under the correct location to make sure that users know about it. There is an internal slack thread for discussion.
Note also that this is documented as a requirement of the 'alerting' plugin that we're using under the hood.