Skip to content

[Security][Detections] Create Threshold-based Rule type #68409

@spong

Description

@spong

This issue is for creating a new rule type based on thresholds/aggregations, and can appear as a separate card for selection within the Define Rule section of the Create Rule flow.

There are actually several kinds of aggregation-based rules that could fall in here: # hits, sum, terms, significant terms, etc.

Latest mocks:

cc @marrasherrier

Metadata

Metadata

Assignees

Labels

Feature:Detection RulesSecurity Solution rules and Detection EngineTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:SIEMenhancementNew value added to drive a business resultv7.9.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions