豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

[Internal]: Moving 'Endpoint Exceptions' to the Management/Assets section and make it per-policy #3883

@gergoabraham

Description

@gergoabraham

Description

We're implementing multiple changes on Endpoint exceptions:

  • moving to a new location

    • the new location is the Security / Management (or Assets) section, next to other endpoint related artifacts like Trusted apps, Event filters etc.
    • similarly to other artifacts, they are available on the Policy details page as a tab
    • they are removed from the 'Shared exception lists' page,
    • they are read-only on the Endpoint Security rule page / Endpoint exception tab
  • per-policy assignment[^1]: similarly to other artifacts, Endpoint exceptions can be assigned globally or per-policy.

    • A pre-requisite for this is that Endpoint exceptions are not duplicated to the Elastic Defend rule as rule exceptions. The documentation issue for that is already created by the detections team: [Internal]: Endpoint exceptions no longer running in Detection Engine #2737
    • But, as this would be a breaking change, we offer the users an opt-in mechanism for per-policy behavior. See this PR for screenshots and video, or the design itself
    • this also means that Endpoint exceptions become space aware. (note, here we state it's global only)
  • import-export: as before, they can be imported/exported, but this is still under design

Planned release

We're developing this continuously behind a feature flag.

  • serverless: As soon as the feature is ready, we're planning to enable the feature flag and release it to serverless. Probably not much earlier as 9.3 feature freeze.
  • ESS: We're targeting 9.3 9.4 on ESS.

Resources

Here's the collection issue containing all implementation issues:

Here's a related doc issue, that change will be released together with the changes in this issue:

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

identical everywhere

What release is this request related to?

9.4

Serverless release

Around 9.3 release, maybe a bit earlier.
Probably as soon as it's ready, sometime in January - will define later.

Collaboration model

The documentation team

Point of contact.

Main contact: @gergoabraham

Stakeholders: @dasansol92 @roxana-gheorghe

Metadata

Metadata

Labels

Team:ExperienceIssues owned by the Experience Docs Team

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions