-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Siem query review #40279
Siem query review #40279
Conversation
Pinging @elastic/secops |
💔 Build Failed |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Amazing work @stephmilovic! I'm so happy by the reduction in code size here. Left two comments in here, and then a few more in https://github.com/elastic/ingest-dev/issues/572.
x-pack/legacy/plugins/siem/server/lib/kpi_hosts/query_authentication.dsl.ts
Outdated
Show resolved
Hide resolved
💚 Build Succeeded |
💚 Build Succeeded |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Even more code removed, love it!
💚 Build Succeeded |
Summary
Implemented @cwurm 's query optimization review: https://github.com/elastic/ingest-dev/issues/572
Please cross reference the issue while reviewing this PR.
This includes:
must
clauses inbool
queries withfilter
term
overmatch_phrase
to get exact matchestrack_total_hits
can befalse
To manually test:
Checklist
Use
strikethroughsto remove checklist items you don't feel are applicable to this PR.This was checked for cross-browser compatibility, including a check against IE11Any text added follows EUI's writing guidelines, uses sentence case text and includes i18n supportDocumentation was added for features that require explanation or tutorialsThis was checked for keyboard-only and screenreader accessibilityFor maintainers
This was checked for breaking API changes and was labeled appropriatelyThis includes a feature addition or change that requires a release note and was labeled appropriately