Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RAC][Alert Triage][Timeline] Create and consume a skeleton Timeline Kibana plugin ☠️ #94380

Closed
3 tasks
andrew-goldstein opened this issue Mar 10, 2021 · 4 comments
Labels
Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Timeline Security Solution Timeline feature Team:Detections and Resp Security Detection Response Team Team:Observability Team label for Observability Team (for things that are handled across all of observability) Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team Theme: rac label obsolete

Comments

@andrew-goldstein
Copy link
Contributor

Create and consume a skeleton Timeline Kibana plugin ☠️

A new Timeline Kibana plugin shall be created to make a common implementation of the Alerts Table Component, which is based on Timeline's table, available in other Kibana apps outside of it's current home in the Security Solution. The new plugin will also make Timeline itself available outside of the Security Solution.

Create a skeleton plugin

Create a skeleton Kibana plugin for Timeline, and consume it as a dependency from the Security Solution.

The existing Timeline code shall not be migrated to the skeleton plugin. (The first migration of exiting Timeline code to the plugin will happen in a separate PR.

Acceptance Criteria

  • The new skeleton Timeline plugin cleanly handles Kibana plugin lifecycle events (e.g. start)
  • The Security Solution is updated to have a dependency on the new plugin
  • The existing Timeline code shall not be migrated to the skeleton plugin
@andrew-goldstein andrew-goldstein added Team:Observability Team label for Observability Team (for things that are handled across all of observability) Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) Team:Detections and Resp Security Detection Response Team Team:Threat Hunting Security Solution Threat Hunting Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Feature:Timeline Security Solution Timeline feature Feature:Detection Alerts Security Solution Detection Alerts Feature Theme: rac label obsolete labels Mar 10, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-alerting-services (Team:Alerting Services)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Detection Alerts Security Solution Detection Alerts Feature Feature:Timeline Security Solution Timeline feature Team:Detections and Resp Security Detection Response Team Team:Observability Team label for Observability Team (for things that are handled across all of observability) Team:ResponseOps Label for the ResponseOps team (formerly the Cases and Alerting teams) Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team Theme: rac label obsolete
Projects
None yet
Development

No branches or pull requests

4 participants