Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Alerting] Expose access to Saved Object References array #85173

Closed
spong opened this issue Dec 7, 2020 · 3 comments
Closed

[Alerting] Expose access to Saved Object References array #85173

spong opened this issue Dec 7, 2020 · 3 comments
Labels
Feature:Alerting Feature:Detection Rules Anything related to Security Solution's Detection Rules Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)

Comments

@spong
Copy link
Member

spong commented Dec 7, 2020

In discussing ways to resolve data integrity issues between Detection Rules and Exception Lists the best path forward seems to be leveraging the existing Saved Object References array, however this isn't currently exposed to those building on top of Alerting SO's. As a workaround, we've been storing our references within AlertParams, which is not searchable, and makes linking back to Rules slow (table scan) unless a back-reference is stored.

@spong spong added Feature:Alerting Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) Feature:Detection Rules Anything related to Security Solution's Detection Rules labels Dec 7, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-alerting-services (Team:Alerting Services)

@mikecote
Copy link
Contributor

Relates to: #87992

@mikecote
Copy link
Contributor

mikecote commented Feb 5, 2021

I noticed we have two issues that will result in the same functionality. I'm going to close this issue in favour of #87992 and move @spong's description to a comment in the other issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Alerting Feature:Detection Rules Anything related to Security Solution's Detection Rules Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams)
Projects
None yet
Development

No branches or pull requests

4 participants