mirror of
https://github.com/elastic/kibana.git
synced 2025-04-24 01:38:56 -04:00
[Security] Drop type EventCorrelationRule, it's really not needed (#113936)
This commit is contained in:
parent
0fe5d26c00
commit
aea3c06316
2 changed files with 3 additions and 8 deletions
|
@ -72,10 +72,6 @@ export interface OverrideRule extends CustomRule {
|
|||
timestampOverride: string;
|
||||
}
|
||||
|
||||
export interface EventCorrelationRule extends CustomRule {
|
||||
language: string;
|
||||
}
|
||||
|
||||
export interface ThreatIndicatorRule extends CustomRule {
|
||||
indicatorIndexPattern: string[];
|
||||
indicatorMappingField: string;
|
||||
|
@ -330,7 +326,7 @@ export const getEqlRule = (): CustomRule => ({
|
|||
maxSignals: 100,
|
||||
});
|
||||
|
||||
export const getCCSEqlRule = (): EventCorrelationRule => ({
|
||||
export const getCCSEqlRule = (): CustomRule => ({
|
||||
customQuery: 'any where process.name == "run-parts"',
|
||||
name: 'New EQL Rule',
|
||||
index: [`${ccsRemoteName}:run-parts`],
|
||||
|
@ -346,7 +342,6 @@ export const getCCSEqlRule = (): EventCorrelationRule => ({
|
|||
lookBack: getLookBack(),
|
||||
timeline: getTimeline(),
|
||||
maxSignals: 100,
|
||||
language: 'eql',
|
||||
});
|
||||
|
||||
export const getEqlSequenceRule = (): CustomRule => ({
|
||||
|
|
|
@ -5,7 +5,7 @@
|
|||
* 2.0.
|
||||
*/
|
||||
|
||||
import { CustomRule, EventCorrelationRule, ThreatIndicatorRule } from '../../objects/rule';
|
||||
import { CustomRule, ThreatIndicatorRule } from '../../objects/rule';
|
||||
|
||||
export const createCustomRule = (rule: CustomRule, ruleId = 'rule_testing', interval = '100m') =>
|
||||
cy.request({
|
||||
|
@ -29,7 +29,7 @@ export const createCustomRule = (rule: CustomRule, ruleId = 'rule_testing', inte
|
|||
failOnStatusCode: false,
|
||||
});
|
||||
|
||||
export const createEventCorrelationRule = (rule: EventCorrelationRule, ruleId = 'rule_testing') =>
|
||||
export const createEventCorrelationRule = (rule: CustomRule, ruleId = 'rule_testing') =>
|
||||
cy.request({
|
||||
method: 'POST',
|
||||
url: 'api/detection_engine/rules',
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue