Skip to content

Add Advanced Analytics (UEBA) sub-category to integrations #499

Closed

Description

Overview

For customer navigation, we'd like to add a new subcategory to integrations, since having all these packages under Security (which has 175 packages) makes it hard to discover.

Category name: Security > Advanced Analytics (UEBA)

Related packages

  • ProblemChild (Living off the Land Detection)
  • DGA
  • DED (Data Exfiltration Detection)
  • LMD (Lateral Movement Detection)

We can make the PRs for these in the integrations repo after this issue/ticket is resolved.

Business & User Value:

  • Users need a convenient view of all ML-based advanced detection packs within their space. We are building additional integration packages under this category. The category will significantly reduce user efforts, reduce user error, and aid in feature discovery.
  • Elastic security (Entity Analytics Onboarding) workflow will leverage this filtered view in the user journey for discovering these packages. Without a reconciled view, the onboarding workflow will remain incomplete.

Implementation tasks

  • Add to package-spec (ref PR)
  • Add to package-registry (ref PR)
  • Release new version of package spec (contact @mrodm)
  • Release new version of elastic-package (contact @mrodm)
  • Release new version of package registry (contact @mrodm)

Mockup:

Screenshot 2023-04-12 at 9 22 19 AM

Related tickets

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Labels

Team:FleetLabel for the Fleet teamenhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions