Skip to content

Conversation

@sdesalas
Copy link
Member

@sdesalas sdesalas commented Oct 31, 2025

RFC: Saved Objects versioning capability

This RFC proposes changes to the Saved Objects service in order to support optional versioning and change tracking capabilities in order to meet security product requirements.

👉 Click for complete RFC - Rendered view 👈

Motivation

Security departments need to comply with an ever increasing set of standards and regulations (DORA, ISO 27001).

As such, users of our security platform are expecting a modern and robust change management process when it comes to modifying their detection rules and related entities such as rule exceptions, which are currently stored in Kibana as Saved Objects (1, 2, 3, 4, 5).

Specifically, users need to be able to show the state of the rule at a specific point in time. They need to be able to review historical changes made to rules, including those that have been deleted. And they also expect the ability revert to a previous state of the rule as needed. They need this for compliance reasons, to understand why the changes were made, as well as to troubleshoot and ensure their correct behaviour.

This is currently one of top SIEM topics in terms of value and impact to our users.

@sdesalas sdesalas self-assigned this Oct 31, 2025
@elasticmachine
Copy link
Contributor

🤖 Jobs for this PR can be triggered through checkboxes. 🚧

ℹ️ To trigger the CI, please tick the checkbox below 👇

  • Click to trigger kibana-pull-request for this PR!
  • Click to trigger kibana-deploy-project-from-pr for this PR!
  • Click to trigger kibana-deploy-cloud-from-pr for this PR!

@sdesalas sdesalas added Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team RFC Feature:Rule Management Security Solution Detection Rule Management area labels Oct 31, 2025
@sdesalas sdesalas changed the title RFC Draft start RFC: Saved Object Versioning Capability Oct 31, 2025
@sdesalas sdesalas changed the title RFC: Saved Object Versioning Capability RFC: Saved Objects versioning capability Oct 31, 2025
@sdesalas sdesalas force-pushed the rfc/saved-object-versioning-capability branch 3 times, most recently from 18906f2 to 2c4b802 Compare October 31, 2025 11:13
@sdesalas sdesalas changed the title RFC: Saved Objects versioning capability [Security Solution] RFC: Saved Objects versioning capability Oct 31, 2025
@sdesalas sdesalas force-pushed the rfc/saved-object-versioning-capability branch from 2c4b802 to e4b62b9 Compare October 31, 2025 12:01
@sdesalas sdesalas closed this Oct 31, 2025
@sdesalas
Copy link
Member Author

sdesalas commented Oct 31, 2025

Please note that this RFC has been moved and is now being hosted as a Google Doc on 👉 this link (internal)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Feature:Rule Management Security Solution Detection Rule Management area RFC Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants