-
Notifications
You must be signed in to change notification settings - Fork 257
[Security][CPS] Document detection rule behavior and correct app availability #8064
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
nastasha-solomon
wants to merge
18
commits into
main
Choose a base branch
from
issue-8050
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
18 commits
Select commit
Hold shift + click to select a range
4209cce
first draft
nastasha-solomon 3dff21c
Merge branch 'main' into issue-8050
nastasha-solomon 8a4589a
Merge branch 'main' into issue-8050
nastasha-solomon 36f2c66
additional edits
nastasha-solomon 5d9d0ed
Merge branch 'main' into issue-8050
nastasha-solomon 0388165
remove comment
nastasha-solomon ffc05eb
Add Value report and SIEM Readiness to origin-project-scoped features
nastasha-solomon d52ada3
Remove accidentally committed docs-builder-mac-arm64.zip.
nastasha-solomon 8b89a4f
Update solutions/_snippets/cps-sec-obs-rules.md
nastasha-solomon 220da37
Update explore-analyze/cross-project-search/_snippets/cps-availabilit…
nastasha-solomon 1a6078a
Update explore-analyze/cross-project-search/_snippets/cps-availabilit…
nastasha-solomon d7c184a
Update explore-analyze/cross-project-search/_snippets/cps-availabilit…
nastasha-solomon d06b056
revert ref and add reminder
nastasha-solomon 267ba11
Merge branch 'main' into issue-8050
nastasha-solomon 8687e7f
Shaina's feedback
nastasha-solomon 28c93a7
Merge branch 'main' into issue-8050
nastasha-solomon b8b8b06
update table
nastasha-solomon 862835a
more editorial feedback
nastasha-solomon File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
42 changes: 30 additions & 12 deletions
42
explore-analyze/cross-project-search/_snippets/cps-availability-security-apps.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,15 +1,33 @@ | ||
| {{elastic-sec}} apps have partial {{cps-init}} support. The following features work across linked projects: | ||
| {{elastic-sec}} apps have partial {{cps-init}} support. The following table shows, for each app, whether the {{cps-init}} scope selector is available and whether you can override that scope in a query. **Read-only** means the app uses the [space default](/deploy-manage/cross-project-search-config/cps-config-access-and-scope.md#cps-default-search-scope) and you can't change it from the header. | ||
|
|
||
| - **Timeline:** Tables display documents from linked projects. Actions that don't apply to remote documents are disabled. | ||
| - **Alert, event, and attack flyouts:** Flyouts render correctly for documents from linked projects. Remote documents are clearly identified, and actions that don't apply to remote documents are hidden or disabled. Investigate in Timeline remains available. | ||
| - **Dashboards:** The Detection & Response and Data Quality dashboards support {{cps-init}}. | ||
| - **Intelligence:** Threat intelligence indicator searches support {{cps-init}}. | ||
| <!-- TODO: After https://github.com/elastic/docs-content/pull/7814 merges, restore the link on "{{ml-cap}}" "read data from linked projects" to /explore-analyze/machine-learning/anomaly-detection/ml-ad-run-jobs.md#ml-ad-cps-scope. --> | ||
| <!-- TBD scope (confirm with Security): Timeline, flyouts, Dashboards, Intelligence, and Defend/Osquery are listed as Read-only (space default). Confirm whether any of these use the session selector (Editable) or search all linked projects. Entity store: confirm federated read is every linked project, not space-scoped. --> | ||
|
|
||
| The following features remain scoped to the origin project: | ||
| | App | {{cps-init}} scope selector | Query-level overrides | | ||
| | --- | --- | --- | | ||
| | **Alert, event, and attack flyouts** | Read-only | Not available | | ||
| | **Alerts** | Not available | Not available | | ||
| | **Attack Discovery** | Not available | Not available | | ||
| | **Cases** | Not available | Not available | | ||
| | **Dashboards** (Detection & Response, Data Quality) | Read-only | Not available | | ||
| | **Detection rules** | Read-only | Available | | ||
| | **{{elastic-defend}} and Osquery** | Read-only | Not available | | ||
| | **Entity store** | Not available | Not available | | ||
| | **Explore page** | Read-only | Not available | | ||
| | **Intelligence** | Read-only | Not available | | ||
| | **{{ml-cap}}** | Read-only | Not available | | ||
| | **Overview page** | Read-only (event widgets); not available (alert widgets) | Not available | | ||
| | **SIEM Readiness** | Not available | Not available | | ||
| | **Timeline** | Read-only | Not available | | ||
| | **Value report** | Not available | Not available | | ||
|
|
||
| - **Alerts:** The Alerts page does not display remote alerts from linked projects. | ||
| - **Explore page:** Host, network, and user exploration searches are scoped to the origin project only. | ||
| - **Entity store:** Entity risk scoring and entity profiles do not include data from linked projects. | ||
| - **Attack Discovery**: AI-generated attack discoveries are based on alerts from the origin project only. | ||
| - **Overview**: The Security Overview page reflects data from the origin project only. | ||
| - **Defend and Osquery**: Elastic Defend and Osquery are scoped to the origin project only. Defend and Osquery are managed through Fleet, meaning their configuration is tied to a single project. Endpoint artifacts, policies, response actions, and Osquery saved queries and packs are managed per project and are not shared across linked projects. | ||
| Some apps have additional limitations: | ||
|
|
||
| - **Alert, event, and attack flyouts:** Documents from linked projects are clearly identified. Actions that don't apply to these documents are hidden or disabled. Investigate in Timeline remains available. Session View isn't available for documents from linked projects. | ||
| - **Alerts:** The Alerts page shows alerts generated by origin project rules, including those created from linked-project data. It doesn't show alerts that a linked project generated on its own. | ||
| - **Cases:** You can't attach an alert or event from a linked project to a case. | ||
| - **Detection rules:** {{esql}} rules support `SET project_routing`. For non-{{esql}} rules that use index patterns, you can use [qualified index expressions](/explore-analyze/cross-project-search/cross-project-search-search.md#search-expressions). Origin rules write alerts to the origin project. The **Max alerts per run** limit applies across the projects the rule queries. A rule searches only the linked projects the user who last saved it can access. For details, refer to [{{cps-cap}} and detection rules](/solutions/security/detect-and-alert/cross-project-search-detection-rules.md). | ||
| - **{{elastic-defend}} and Osquery:** The **Endpoints** page, host details, **Response actions history**, and Osquery query results include data from linked projects. Policies, artifacts, response action dispatch, and Osquery saved queries and packs stay per project because they're managed through Fleet. | ||
| - **Entity store:** Origin profiles include entities from every linked project. Each project still builds its own store, and risk scoring stays on the origin project. A host that appears in more than one project isn't combined into a single entity at the origin. | ||
| - **{{ml-cap}}:** {{anomaly-detect-cap}} job {{dfeeds}} can read data from linked projects. Jobs and results are stored on the origin project. {{ml-cap}} rules alert on those stored results, including anomalies produced from linked-project data. | ||
| - **Timeline:** Tables display documents from linked projects. Actions that don't apply to documents in linked projects are disabled. | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. this looks very similar to the stuff on create-manage-rules now ... should they all use a single snippet? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,10 +1,13 @@ | ||
|
|
||
| When [{{cps}}](/explore-analyze/cross-project-search.md) is enabled and you have [linked projects](/deploy-manage/cross-project-search-config/cps-config-link-and-manage.md), rules query data across linked projects based on the **space-level {{cps}} scope**. | ||
|
|
||
| For how {{cps}} applies when you create or edit rules (space-level scope, the read-only scope selector, and query-level overrides) refer to [{{cps-cap}} availability by app](/explore-analyze/cross-project-search/cross-project-search-manage-scope.md#cps-availability). | ||
| When you create or edit a rule, the [{{cps-init}} scope selector](/explore-analyze/cross-project-search/cross-project-search-manage-scope.md#cps-in-kibana) in the header shows the current {{cps}} scope but is read-only. To change which projects most rules query, update the [{{cps}} scope configured for the space](/deploy-manage/cross-project-search-config/cps-config-access-and-scope.md#cps-default-search-scope). | ||
|
|
||
| You can't select a {{cps}} scope for an individual rule in the header. These rule types can still control which projects they query: | ||
|
|
||
| - **{{esql}} rules:** Add [`SET project_routing`](/explore-analyze/cross-project-search/cross-project-search-project-routing.md) at the start of the rule query to override the space-level scope. | ||
| - **Rules that use index patterns:** Use [qualified index expressions](/explore-analyze/cross-project-search/cross-project-search-search.md#search-expressions) in the index pattern to target specific projects. | ||
| - **{{ml-cap}} rules:** These rules alert on {{anomaly-detect}} results stored on the origin project. {{anomaly-jobs-cap}} can read linked-project data; jobs and results stay on the origin. | ||
|
|
||
| For prerequisites such as linking projects and configuring default scope, refer to [{{cps-cap}}](/explore-analyze/cross-project-search.md) and [Configure {{cps}} access and scope](/deploy-manage/cross-project-search-config/cps-config-access-and-scope.md). | ||
| <!-- TODO: After https://github.com/elastic/docs-content/pull/7814 merges, restore the link on "can read linked-project data" to /explore-analyze/machine-learning/anomaly-detection/ml-ad-run-jobs.md#ml-ad-cps-scope. --> | ||
|
|
||
| :::{note} | ||
| {{ml-cap}} rules don't support {{cps}}; they search data in the origin project only. Other features also have limited or no {{cps}} support. For details, refer to [{{cps-cap}} availability by app](/explore-analyze/cross-project-search/cross-project-search-manage-scope.md#cps-availability). | ||
| ::: | ||
| For prerequisites such as linking projects and configuring default scope, refer to [](/explore-analyze/cross-project-search.md) and [](/deploy-manage/cross-project-search-config/cps-config-access-and-scope.md). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think using the query-level overrides column for some of these details can lead to a little confusion. looking at the ML row specifically, the details in the query-level overrides are mostly about how CPS is supported in the feature. consider moving this to another column, or renaming the column to something like "Details" since only one of your features support query-level overrides (nor would we expect the others to).
the pattern observability uses is that it defers these details to a dedicated page. that's an option but perhaps too heavy