Skip to content

[ML] Adding new jobs to siem module - #43783

Merged
jgowdyelastic merged 12 commits into
elastic:masterfrom
jgowdyelastic:adding-new-siem-jobs
Aug 29, 2019
Merged

jgowdyelastic merged 12 commits into
elastic:masterfrom
jgowdyelastic:adding-new-siem-jobs

Conversation

@jgowdyelastic

@jgowdyelastic jgowdyelastic commented Aug 22, 2019 •

Copy link
Copy Markdown
Member

Adding new jobs to the Siem Auditbeat and Winlogbeat modules.

siem_auditbeat_ecs
linux_anomalous_network_activity
linux_anomalous_network_port_activity
linux_anomalous_network_service
linux_anomalous_network_url_activity
linux_anomalous_process_all_hosts
linux_anomalous_user_name
rare_process_by_host_linux_ecs
suspicious_login_activity_ecs

siem_winlogbeat_ecs
rare_process_windows_ecs
windows_anomalous_network_activity
windows_anomalous_path_activity
windows_anomalous_process_all_hosts
windows_anomalous_process_creation
windows_anomalous_script
windows_anomalous_service
windows_anomalous_user_name

Checklist

Use strikethroughs to remove checklist items you don't feel are applicable to this PR.

For maintainers

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

@elasticmachine

Copy link
Copy Markdown
Contributor

Pinging @elastic/ml-ui

@elasticmachine

Copy link
Copy Markdown
Contributor

Pinging @elastic/siem

@cwurm

cwurm commented Aug 23, 2019

Copy link
Copy Markdown
Contributor

Looking through the queries, a few questions:

  1. must vs filter: In boolean queries we use must, sometimes filter. I think we should always use the faster (because non-scoring) filter.
  2. match vs term We sometimes use match and sometimes term. I'm not sure the behavior is different on keyword fields where match cannot do any text analysis - but regardless maybe we should be consistent and use term everywhere?
  3. minimum_should_match We often exclude multiple values using should clauses with multiple sub-clauses. In such cases, I've often seen "minimum_should_match" : 1 used since only one match is enough to exclude a document. So I wonder, would using it give us a performance advantage? Or is the boolean query smart enough to figure out that a should inside a must_not already implies it?

I focus on the queries mainly because with an increasing number of built-in jobs the query performance might matter, esp. when a user starts them all at once.

@sophiec20

Copy link
Copy Markdown
Contributor

@blaklaybul along with the above, can we please consider "model_memory_limit": "256mb" ... for count by field detectors this is way too high and will prevent multiple jobs being opened in quick succession on small nodes (especially a cloud trial). Ref #41135

@blaklaybul

blaklaybul commented Aug 23, 2019 •

Copy link
Copy Markdown
Contributor

@cwurm thanks for the feedback on the queries. I'll continue to refine them using your suggestions.

@sophiec20 absolutely. I was using 256mb as a placeholder while I go through the model_memory_stats from the jobs, which is ongoing.

Some of the linux jobs consumed a lot of memory, some as high as 3.5gb. Also, we do not have figures for the windows jobs. Being that the windows jobs were not developed on a cluster, all we have for estimating model size is using the data from another cluster. This has more data than what we used to develop the initial set of SIEM jobs.

So based on seen or assumed high memory sizes, I think we should hold the following jobs so we can continue to refine them and test them on real world datasets:

  • file_deletes_linux_ecs.json (3.5GB)
  • file_events_linux_ecs.json (1.5 GB)
  • file_events_windows_ecs.json (assumed 1.5GB)
  • rare_destination_port_process_windows_ecs.json (potential high cardinality partition field)
  • rare_process_tree_windows_ecs.json (potential high cardinality partition field)

cc @randomuserid

@randomuserid

randomuserid commented Aug 23, 2019 •

Copy link
Copy Markdown
Contributor

On the proposed cuts:

file_deletes_linux_ecs.json (3.5GB)
file_events_linux_ecs.json (1.5 GB)

  • I'm OK with holding these

file_events_windows_ecs.json (assumed 1.5GB)
rare_process_tree_windows_ecs.json (potential high cardinality partition field)

-these are canonical hunts; the second is actually taught in threat hunting school , so losing them would be a bit of a shame.

rare_destination_port_process_windows_ecs.json (potential high cardinality partition field)

  • this could be replaced by the rare network process job

They have asked for a number of things and I'd like to include two more jobs I have tested using their ideas - rare network process and rare process arguments. These jobs are testing OK and are good hunts so it would be valuable to include them.

@blaklaybul

blaklaybul commented Aug 27, 2019 •

Copy link
Copy Markdown
Contributor

Thanks for the feedback everyone. @randomuserid and I have finalized the jobs configs, datafeed queries, custom urls, model memory limits, and naming - bringing us to a total of 13 new jobs. The final jobs can be found here:

@jgowdyelastic note that the final list of jobs (and their names) have changed for consistency and ease of use within the SIEM app.

Additionally, we will need to update the manifest descriptions and queries to reflect the new jobs:

siem-auditbeat:

{
"description": "Detect unusual behavior in Auditbeat ECS data (beta)"`, 
"query": {
    "bool": {
      "filter": [
        { "term": { "agent.type": "auditbeat" } }
      ]
    }
  }
}

siem-winlogbeat:

{
"description": "Detect unusual behavior in Winlogbeat ECS data (beta)"`, 
"query": {
    "bool": {
      "filter": [
        { "term": { "agent.type": "winlogbeat" } }
      ]
    }
  }
}

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

@cwurm

cwurm commented Aug 27, 2019

Copy link
Copy Markdown
Contributor

I still see one must clause and several match queries. Can we change those to filter and term?

@jgowdyelastic
jgowdyelastic marked this pull request as ready for review August 27, 2019 12:36
@jgowdyelastic
jgowdyelastic requested a review from a team as a code owner August 27, 2019 12:36
@elasticmachine

Copy link
Copy Markdown
Contributor

💔 Build Failed

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

@jgowdyelastic
jgowdyelastic merged commit 64ec780 into elastic:master Aug 29, 2019
@jgowdyelastic
jgowdyelastic deleted the adding-new-siem-jobs branch August 29, 2019 09:32
jgowdyelastic added a commit to jgowdyelastic/kibana that referenced this pull request Aug 29, 2019
* [ML] Adding new jobs to siem module

* updating descriptions

* removing new jobs

* updating manifests

* adding updated modules

* updating queries

* fixing detector

* updating job descriptions

* updating datafeed ids

* changing duplicate description

* changing match for term

* adding (beta) to descriptions
jgowdyelastic added a commit that referenced this pull request Aug 29, 2019
* [ML] Adding new jobs to siem module

* updating descriptions

* removing new jobs

* updating manifests

* adding updated modules

* updating queries

* fixing detector

* updating job descriptions

* updating datafeed ids

* changing duplicate description

* changing match for term

* adding (beta) to descriptions
spong added a commit that referenced this pull request Aug 29, 2019
## Summary
Adds the below new ML Jobs from #43783 and #44383 for the SIEM ML Integration.

Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5.

``` ts
  {
    name: 'siem_auditbeat_ecs',
    defaultIndexPattern: 'auditbeat-*',
    jobs: [
      'rare_process_by_host_linux_ecs',
      'suspicious_login_activity_ecs',
      'linux_anomalous_network_activity_ecs',
      'linux_anomalous_network_port_activity_ecs',
      'linux_anomalous_network_service',
      'linux_anomalous_network_url_activity_ecs',
      'linux_anomalous_process_all_hosts_ecs',
      'linux_anomalous_user_name_ecs',
    ],
  },
  {
    name: 'siem_winlogbeat_ecs',
    defaultIndexPattern: 'winlogbeat-*',
    jobs: [
      'rare_process_by_host_windows_ecs',
      'windows_anomalous_network_activity_ecs',
      'windows_anomalous_path_activity_ecs',
      'windows_anomalous_process_all_hosts_ecs',
      'windows_anomalous_process_creation',
      'windows_anomalous_script',
      'windows_anomalous_service',
      'windows_anomalous_user_name_ecs',
    ],
  },
```

### Checklist

Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR.

- [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~
- [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~
- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials
  * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add?
- [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~
- [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~

### For maintainers

- [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
- [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
spong added a commit to spong/kibana that referenced this pull request Aug 30, 2019
## Summary
Adds the below new ML Jobs from elastic#43783 and elastic#44383 for the SIEM ML Integration.

Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5.

``` ts
  {
    name: 'siem_auditbeat_ecs',
    defaultIndexPattern: 'auditbeat-*',
    jobs: [
      'rare_process_by_host_linux_ecs',
      'suspicious_login_activity_ecs',
      'linux_anomalous_network_activity_ecs',
      'linux_anomalous_network_port_activity_ecs',
      'linux_anomalous_network_service',
      'linux_anomalous_network_url_activity_ecs',
      'linux_anomalous_process_all_hosts_ecs',
      'linux_anomalous_user_name_ecs',
    ],
  },
  {
    name: 'siem_winlogbeat_ecs',
    defaultIndexPattern: 'winlogbeat-*',
    jobs: [
      'rare_process_by_host_windows_ecs',
      'windows_anomalous_network_activity_ecs',
      'windows_anomalous_path_activity_ecs',
      'windows_anomalous_process_all_hosts_ecs',
      'windows_anomalous_process_creation',
      'windows_anomalous_script',
      'windows_anomalous_service',
      'windows_anomalous_user_name_ecs',
    ],
  },
```

### Checklist

Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR.

- [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~
- [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~
- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials
  * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add?
- [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~
- [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~

### For maintainers

- [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
- [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
spong added a commit to spong/kibana that referenced this pull request Aug 30, 2019
## Summary
Adds the below new ML Jobs from elastic#43783 and elastic#44383 for the SIEM ML Integration.

Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5.

``` ts
  {
    name: 'siem_auditbeat_ecs',
    defaultIndexPattern: 'auditbeat-*',
    jobs: [
      'rare_process_by_host_linux_ecs',
      'suspicious_login_activity_ecs',
      'linux_anomalous_network_activity_ecs',
      'linux_anomalous_network_port_activity_ecs',
      'linux_anomalous_network_service',
      'linux_anomalous_network_url_activity_ecs',
      'linux_anomalous_process_all_hosts_ecs',
      'linux_anomalous_user_name_ecs',
    ],
  },
  {
    name: 'siem_winlogbeat_ecs',
    defaultIndexPattern: 'winlogbeat-*',
    jobs: [
      'rare_process_by_host_windows_ecs',
      'windows_anomalous_network_activity_ecs',
      'windows_anomalous_path_activity_ecs',
      'windows_anomalous_process_all_hosts_ecs',
      'windows_anomalous_process_creation',
      'windows_anomalous_script',
      'windows_anomalous_service',
      'windows_anomalous_user_name_ecs',
    ],
  },
```

### Checklist

Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR.

- [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~
- [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~
- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials
  * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add?
- [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~
- [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~

### For maintainers

- [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
- [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
andrew-goldstein pushed a commit that referenced this pull request Aug 30, 2019
## Summary
Adds the below new ML Jobs from #43783 and #44383 for the SIEM ML Integration.

Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5.

``` ts
  {
    name: 'siem_auditbeat_ecs',
    defaultIndexPattern: 'auditbeat-*',
    jobs: [
      'rare_process_by_host_linux_ecs',
      'suspicious_login_activity_ecs',
      'linux_anomalous_network_activity_ecs',
      'linux_anomalous_network_port_activity_ecs',
      'linux_anomalous_network_service',
      'linux_anomalous_network_url_activity_ecs',
      'linux_anomalous_process_all_hosts_ecs',
      'linux_anomalous_user_name_ecs',
    ],
  },
  {
    name: 'siem_winlogbeat_ecs',
    defaultIndexPattern: 'winlogbeat-*',
    jobs: [
      'rare_process_by_host_windows_ecs',
      'windows_anomalous_network_activity_ecs',
      'windows_anomalous_path_activity_ecs',
      'windows_anomalous_process_all_hosts_ecs',
      'windows_anomalous_process_creation',
      'windows_anomalous_script',
      'windows_anomalous_service',
      'windows_anomalous_user_name_ecs',
    ],
  },
```

### Checklist

Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR.

- [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~
- [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~
- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials
  * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add?
- [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~
- [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~

### For maintainers

- [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
- [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
andrew-goldstein pushed a commit that referenced this pull request Aug 30, 2019
## Summary
Adds the below new ML Jobs from #43783 and #44383 for the SIEM ML Integration.

Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5.

``` ts
  {
    name: 'siem_auditbeat_ecs',
    defaultIndexPattern: 'auditbeat-*',
    jobs: [
      'rare_process_by_host_linux_ecs',
      'suspicious_login_activity_ecs',
      'linux_anomalous_network_activity_ecs',
      'linux_anomalous_network_port_activity_ecs',
      'linux_anomalous_network_service',
      'linux_anomalous_network_url_activity_ecs',
      'linux_anomalous_process_all_hosts_ecs',
      'linux_anomalous_user_name_ecs',
    ],
  },
  {
    name: 'siem_winlogbeat_ecs',
    defaultIndexPattern: 'winlogbeat-*',
    jobs: [
      'rare_process_by_host_windows_ecs',
      'windows_anomalous_network_activity_ecs',
      'windows_anomalous_path_activity_ecs',
      'windows_anomalous_process_all_hosts_ecs',
      'windows_anomalous_process_creation',
      'windows_anomalous_script',
      'windows_anomalous_service',
      'windows_anomalous_user_name_ecs',
    ],
  },
```

### Checklist

Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR.

- [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~
- [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~
- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials
  * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add?
- [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~
- [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~

### For maintainers

- [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
- [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request May 6, 2026
* [ML] Adding new jobs to siem module

* updating descriptions

* removing new jobs

* updating manifests

* adding updated modules

* updating queries

* fixing detector

* updating job descriptions

* updating datafeed ids

* changing duplicate description

* changing match for term

* adding (beta) to descriptions
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request May 6, 2026
## Summary
Adds the below new ML Jobs from elastic#43783 and elastic#44383 for the SIEM ML Integration.

Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5.

``` ts
  {
    name: 'siem_auditbeat_ecs',
    defaultIndexPattern: 'auditbeat-*',
    jobs: [
      'rare_process_by_host_linux_ecs',
      'suspicious_login_activity_ecs',
      'linux_anomalous_network_activity_ecs',
      'linux_anomalous_network_port_activity_ecs',
      'linux_anomalous_network_service',
      'linux_anomalous_network_url_activity_ecs',
      'linux_anomalous_process_all_hosts_ecs',
      'linux_anomalous_user_name_ecs',
    ],
  },
  {
    name: 'siem_winlogbeat_ecs',
    defaultIndexPattern: 'winlogbeat-*',
    jobs: [
      'rare_process_by_host_windows_ecs',
      'windows_anomalous_network_activity_ecs',
      'windows_anomalous_path_activity_ecs',
      'windows_anomalous_process_all_hosts_ecs',
      'windows_anomalous_process_creation',
      'windows_anomalous_script',
      'windows_anomalous_service',
      'windows_anomalous_user_name_ecs',
    ],
  },
```

### Checklist

Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR.

- [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~
- [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~
- [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials
  * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add?
- [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~
- [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~

### For maintainers

- [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
- [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants