Update Entity related Kibana prebuilt ML rules with new _ea ML job ID and update minimum stack versions#5794
Conversation
|
⛔️ Test failed Results
|
Rule: Tuning - GuidelinesThese guidelines serve as a reminder set of considerations when tuning an existing rule. Documentation and Context
Rule Metadata Checks
Testing and Validation
|
| license = "Elastic License v2" | ||
| machine_learning_job_id = "rare_method_for_a_username" | ||
| machine_learning_job_id = "rare_method_for_a_username_euid" | ||
| name = "Unusual AWS Command for a User" |
There was a problem hiding this comment.
@susan-shu-c Could you confirm the process to update the investigation guide?
There was a problem hiding this comment.
On it, pending response!
There was a problem hiding this comment.
For new rules: there is a process to kick off, we now have permissions
For existing rules: manually edit
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
_ea ML job ID and update minimum stack versions
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
Confirmed that all of 105 ML jobs referenced here match the corresponding branches in Kibana/integrations |
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
|
I've also added a new rule Commit with the new rule: 13179fd I based the new rule off these two existing/similar rules, but requesting review: rules/ml/execution_ml_windows_anomalous_script.toml
rules/ml/persistence_ml_rare_process_by_host_windows.toml
|
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
…ions branch) DED, DGA, LMD, PAD, and ProblemChild ML rule changes have been moved to the euid-rules-update-integrations branch which corresponds to integrations#17626. This branch (euid-rules-update) now only contains Kibana-related ML rule changes. Made-with: Cursor
Resolves conflicts with main's "Add Supplemental Mitre Mappings" commit (#5876). Conflict resolution strategy: - Kept our _ea ML job ID changes and min_stack_version = "9.4.0" - Incorporated main's new supplemental MITRE technique mappings - Set updated_date = "2026/04/01" for all conflicted files Made-with: Cursor
|
⛔️ Test failed Results
|
Made-with: Cursor
…user rules Made-with: Cursor
|
⛔️ Test failed Results
|
|
⛔️ Test failed Results
|
_ea ML job ID and update minimum stack versions_ea ML job ID and update minimum stack versions
|
⛔️ Test failed Results
|
Pull Request
Issue link(s):
Summary - What I changed
Corresponds with changes to ML jobs in
This PR will:
_easuffixHow To Test
Checklist
bug,enhancement,schema,maintenance,Rule: New,Rule: Deprecation,Rule: Tuning,Hunt: New, orHunt: Tuningso guidelines can be generatedmeta:rapid-mergelabel if planning to merge within 24 hoursContributor checklist