Repository navigation
[ML] Adding new jobs to siem module - #43783
Conversation
💚 Build Succeeded |
77dcf5d to
218d884
Compare
💚 Build Succeeded |
|
Pinging @elastic/ml-ui |
|
Pinging @elastic/siem |
|
Looking through the queries, a few questions:
I focus on the queries mainly because with an increasing number of built-in jobs the query performance might matter, esp. when a user starts them all at once. |
|
@blaklaybul along with the above, can we please consider |
|
@cwurm thanks for the feedback on the queries. I'll continue to refine them using your suggestions. @sophiec20 absolutely. I was using Some of the linux jobs consumed a lot of memory, some as high as So based on seen or assumed high memory sizes, I think we should hold the following jobs so we can continue to refine them and test them on real world datasets:
|
|
On the proposed cuts: file_deletes_linux_ecs.json (3.5GB)
file_events_windows_ecs.json (assumed 1.5GB) -these are canonical hunts; the second is actually taught in threat hunting school , so losing them would be a bit of a shame. rare_destination_port_process_windows_ecs.json (potential high cardinality partition field)
They have asked for a number of things and I'd like to include two more jobs I have tested using their ideas - rare network process and rare process arguments. These jobs are testing OK and are good hunts so it would be valuable to include them. |
|
Thanks for the feedback everyone. @randomuserid and I have finalized the jobs configs, datafeed queries, custom urls, model memory limits, and naming - bringing us to a total of 13 new jobs. The final jobs can be found here: @jgowdyelastic note that the final list of jobs (and their names) have changed for consistency and ease of use within the SIEM app. Additionally, we will need to update the manifest descriptions and queries to reflect the new jobs: siem-auditbeat:siem-winlogbeat: |
💚 Build Succeeded |
💚 Build Succeeded |
|
I still see one |
f66fd5f to
e1deb52
Compare
e1deb52 to
dff1a98
Compare
💔 Build Failed |
87979c6 to
2ea172f
Compare
💚 Build Succeeded |
* [ML] Adding new jobs to siem module * updating descriptions * removing new jobs * updating manifests * adding updated modules * updating queries * fixing detector * updating job descriptions * updating datafeed ids * changing duplicate description * changing match for term * adding (beta) to descriptions
* [ML] Adding new jobs to siem module * updating descriptions * removing new jobs * updating manifests * adding updated modules * updating queries * fixing detector * updating job descriptions * updating datafeed ids * changing duplicate description * changing match for term * adding (beta) to descriptions
## Summary Adds the below new ML Jobs from #43783 and #44383 for the SIEM ML Integration. Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5. ``` ts { name: 'siem_auditbeat_ecs', defaultIndexPattern: 'auditbeat-*', jobs: [ 'rare_process_by_host_linux_ecs', 'suspicious_login_activity_ecs', 'linux_anomalous_network_activity_ecs', 'linux_anomalous_network_port_activity_ecs', 'linux_anomalous_network_service', 'linux_anomalous_network_url_activity_ecs', 'linux_anomalous_process_all_hosts_ecs', 'linux_anomalous_user_name_ecs', ], }, { name: 'siem_winlogbeat_ecs', defaultIndexPattern: 'winlogbeat-*', jobs: [ 'rare_process_by_host_windows_ecs', 'windows_anomalous_network_activity_ecs', 'windows_anomalous_path_activity_ecs', 'windows_anomalous_process_all_hosts_ecs', 'windows_anomalous_process_creation', 'windows_anomalous_script', 'windows_anomalous_service', 'windows_anomalous_user_name_ecs', ], }, ``` ### Checklist Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR. - [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~ - [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~ - [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add? - [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~ - [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~ ### For maintainers - [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~ - [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
## Summary Adds the below new ML Jobs from elastic#43783 and elastic#44383 for the SIEM ML Integration. Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5. ``` ts { name: 'siem_auditbeat_ecs', defaultIndexPattern: 'auditbeat-*', jobs: [ 'rare_process_by_host_linux_ecs', 'suspicious_login_activity_ecs', 'linux_anomalous_network_activity_ecs', 'linux_anomalous_network_port_activity_ecs', 'linux_anomalous_network_service', 'linux_anomalous_network_url_activity_ecs', 'linux_anomalous_process_all_hosts_ecs', 'linux_anomalous_user_name_ecs', ], }, { name: 'siem_winlogbeat_ecs', defaultIndexPattern: 'winlogbeat-*', jobs: [ 'rare_process_by_host_windows_ecs', 'windows_anomalous_network_activity_ecs', 'windows_anomalous_path_activity_ecs', 'windows_anomalous_process_all_hosts_ecs', 'windows_anomalous_process_creation', 'windows_anomalous_script', 'windows_anomalous_service', 'windows_anomalous_user_name_ecs', ], }, ``` ### Checklist Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR. - [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~ - [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~ - [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add? - [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~ - [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~ ### For maintainers - [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~ - [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
## Summary Adds the below new ML Jobs from elastic#43783 and elastic#44383 for the SIEM ML Integration. Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5. ``` ts { name: 'siem_auditbeat_ecs', defaultIndexPattern: 'auditbeat-*', jobs: [ 'rare_process_by_host_linux_ecs', 'suspicious_login_activity_ecs', 'linux_anomalous_network_activity_ecs', 'linux_anomalous_network_port_activity_ecs', 'linux_anomalous_network_service', 'linux_anomalous_network_url_activity_ecs', 'linux_anomalous_process_all_hosts_ecs', 'linux_anomalous_user_name_ecs', ], }, { name: 'siem_winlogbeat_ecs', defaultIndexPattern: 'winlogbeat-*', jobs: [ 'rare_process_by_host_windows_ecs', 'windows_anomalous_network_activity_ecs', 'windows_anomalous_path_activity_ecs', 'windows_anomalous_process_all_hosts_ecs', 'windows_anomalous_process_creation', 'windows_anomalous_script', 'windows_anomalous_service', 'windows_anomalous_user_name_ecs', ], }, ``` ### Checklist Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR. - [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~ - [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~ - [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add? - [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~ - [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~ ### For maintainers - [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~ - [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
## Summary Adds the below new ML Jobs from #43783 and #44383 for the SIEM ML Integration. Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5. ``` ts { name: 'siem_auditbeat_ecs', defaultIndexPattern: 'auditbeat-*', jobs: [ 'rare_process_by_host_linux_ecs', 'suspicious_login_activity_ecs', 'linux_anomalous_network_activity_ecs', 'linux_anomalous_network_port_activity_ecs', 'linux_anomalous_network_service', 'linux_anomalous_network_url_activity_ecs', 'linux_anomalous_process_all_hosts_ecs', 'linux_anomalous_user_name_ecs', ], }, { name: 'siem_winlogbeat_ecs', defaultIndexPattern: 'winlogbeat-*', jobs: [ 'rare_process_by_host_windows_ecs', 'windows_anomalous_network_activity_ecs', 'windows_anomalous_path_activity_ecs', 'windows_anomalous_process_all_hosts_ecs', 'windows_anomalous_process_creation', 'windows_anomalous_script', 'windows_anomalous_service', 'windows_anomalous_user_name_ecs', ], }, ``` ### Checklist Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR. - [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~ - [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~ - [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add? - [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~ - [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~ ### For maintainers - [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~ - [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
## Summary Adds the below new ML Jobs from #43783 and #44383 for the SIEM ML Integration. Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5. ``` ts { name: 'siem_auditbeat_ecs', defaultIndexPattern: 'auditbeat-*', jobs: [ 'rare_process_by_host_linux_ecs', 'suspicious_login_activity_ecs', 'linux_anomalous_network_activity_ecs', 'linux_anomalous_network_port_activity_ecs', 'linux_anomalous_network_service', 'linux_anomalous_network_url_activity_ecs', 'linux_anomalous_process_all_hosts_ecs', 'linux_anomalous_user_name_ecs', ], }, { name: 'siem_winlogbeat_ecs', defaultIndexPattern: 'winlogbeat-*', jobs: [ 'rare_process_by_host_windows_ecs', 'windows_anomalous_network_activity_ecs', 'windows_anomalous_path_activity_ecs', 'windows_anomalous_process_all_hosts_ecs', 'windows_anomalous_process_creation', 'windows_anomalous_script', 'windows_anomalous_service', 'windows_anomalous_user_name_ecs', ], }, ``` ### Checklist Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR. - [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~ - [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~ - [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add? - [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~ - [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~ ### For maintainers - [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~ - [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
* [ML] Adding new jobs to siem module * updating descriptions * removing new jobs * updating manifests * adding updated modules * updating queries * fixing detector * updating job descriptions * updating datafeed ids * changing duplicate description * changing match for term * adding (beta) to descriptions
## Summary Adds the below new ML Jobs from elastic#43783 and elastic#44383 for the SIEM ML Integration. Note: This also removes the `siem-api-` prefix added when jobs are initially created. As a result, upgrading users who have any of the three original jobs (`rare_process_linux_ecs`, `suspicious_login_activity_ecs`, `rare_process_windows_ecs`) installed, will have the latest version of them installed without the prefix. The old `siem-api-` prefixed jobs will then show up in the `Custom jobs` tab within the UI. This was going to happen with the `rare_process_linux_ecs` anyway, as it was renamed to `rare_process_by_host_linux_ecs`, so we took the opportunity to clean up naming while the job count is low. Job versioning/migration will be addressed in 7.5. ``` ts { name: 'siem_auditbeat_ecs', defaultIndexPattern: 'auditbeat-*', jobs: [ 'rare_process_by_host_linux_ecs', 'suspicious_login_activity_ecs', 'linux_anomalous_network_activity_ecs', 'linux_anomalous_network_port_activity_ecs', 'linux_anomalous_network_service', 'linux_anomalous_network_url_activity_ecs', 'linux_anomalous_process_all_hosts_ecs', 'linux_anomalous_user_name_ecs', ], }, { name: 'siem_winlogbeat_ecs', defaultIndexPattern: 'winlogbeat-*', jobs: [ 'rare_process_by_host_windows_ecs', 'windows_anomalous_network_activity_ecs', 'windows_anomalous_path_activity_ecs', 'windows_anomalous_process_all_hosts_ecs', 'windows_anomalous_process_creation', 'windows_anomalous_script', 'windows_anomalous_service', 'windows_anomalous_user_name_ecs', ], }, ``` ### Checklist Use ~~strikethroughs~~ to remove checklist items you don't feel are applicable to this PR. - [ ] ~This was checked for cross-browser compatibility, [including a check against IE11](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility)~ - [ ] ~Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/master/packages/kbn-i18n/README.md)~ - [ ] [Documentation](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#writing-documentation) was added for features that require explanation or tutorials * Will work with @benskelker to update the job list in the [SIEM Guide](https://www.elastic.co/guide/en/siem/guide/current/machine-learning.html). @randomuserid, is there any additional documentation you would like to add? - [ ] ~[Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios~ - [ ] ~This was checked for [keyboard-only and screenreader accessibility](https://developer.mozilla.org/en-US/docs/Learn/Tools_and_testing/Cross_browser_testing/Accessibility#Accessibility_testing_checklist)~ ### For maintainers - [ ] ~This was checked for breaking API changes and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~ - [ ] ~This includes a feature addition or change that requires a release note and was [labeled appropriately](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#release-notes-process)~
Adding new jobs to the Siem Auditbeat and Winlogbeat modules.
siem_auditbeat_ecs
linux_anomalous_network_activitylinux_anomalous_network_port_activitylinux_anomalous_network_servicelinux_anomalous_network_url_activitylinux_anomalous_process_all_hostslinux_anomalous_user_namerare_process_by_host_linux_ecssuspicious_login_activity_ecssiem_winlogbeat_ecs
rare_process_windows_ecswindows_anomalous_network_activitywindows_anomalous_path_activitywindows_anomalous_process_all_hostswindows_anomalous_process_creationwindows_anomalous_scriptwindows_anomalous_servicewindows_anomalous_user_nameChecklist
Use
strikethroughsto remove checklist items you don't feel are applicable to this PR.For maintainers