Changed the job to work with a dedicated index (#42297) (#42465)

## Summary

Summarize your PR. If it involves visual changes include a screenshot or gif.

### Checklist

Uses a dedicated index for job creation instead of the shared anomaly index.

Previously we used only `.ml-anomalies-shared` but this can cause a mapping clash from users who might have put different data types into that index already.

See:
https://www.elastic.co/guide/en/elastic-stack-overview/7.x/ml-mappingclash.html

This makes all creation of all SIEM jobs use a dedicated index from this point moving forward. 

For testing:

* Delete any existing jobs from your server and any test data in the ML UI:
* Go to dev tools and run: `GET /_cat/indices/.ml-anomalies-custom-*?v` and verify you do not have any custom indexes prefixed with an existing SIEM job 
* Click the "Anomaly Button" in the SIEM application to re-install the jobs
* Go to dev tools and run: `GET /_cat/indices/.ml-*?v`

Expectations are that you will see these indexes created:

```ts
health status index                                                          uuid                   pri rep docs.count docs.deleted store.size pri.store.size
green  open   .ml-anomalies-custom-siem-api-suspicious_login_activity_ecs    7ksvxOpgQ8WOG91NA_o8Eg   1   0       1474         1905    601.8kb        601.8kb
green  open   .ml-anomalies-custom-siem-api-rare_process_windows_ecs         Q_8xC5orR-eZSlXQJvmL9w   1   0       1655          474    454.3kb        454.3kb
green  open   .ml-anomalies-custom-siem-api-rare_process_linux_ecs           k_MwtbZIRbSkQxh6lcXIKg   1   0       1845         3832        1mb            1mb
```

~~- [ ] This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~~

- [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)

~~- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials~~

~~- [ ] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~~

~~- [ ] This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~~

### For maintainers

~~- [ ] This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~~

- [x] This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)
This commit is contained in:
Garrett Spong 2019-08-02 07:35:11 -06:00 committed by GitHub
parent 7dcf815049
commit db2d3141c5
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -63,7 +63,7 @@ export const setupMlJob = async ({
groups,
indexPatternName,
startDatafeed: false,
useDedicatedIndex: false,
useDedicatedIndex: true,
}),
headers: {
'kbn-system-api': 'true',