Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Give user the ability to cancel a long running rule execution #93740

Open
Tracked by #165878
peluja1012 opened this issue Mar 5, 2021 · 2 comments
Labels
consider-next dependencies Pull requests that update a dependency file enhancement New value added to drive a business result Feature:Rule Management Security Solution Detection Rule Management area needs design sdh-linked Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: simp_prot_mgmt Security Solution Simplified Protection Management Theme

Comments

@peluja1012
Copy link
Contributor

Currently there is no way to cancel rule execution. When a user "deactivates" (by clicking the "deactivate" button) a rule, it will simply not schedule the following rule execution task, but the current task will continue to run until finished.

In practice, users have experienced that some long running rules like Indicator Match rules continue to run for ~30 minutes after "deactivation". These long running rules could be performance intensive and affect the user's cluster, leaving the user with an undesirable user experience in the app until the rule execution finishes.

We should allow users to cancel rule execution, if desired.

@peluja1012 peluja1012 added enhancement New value added to drive a business result Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. labels Mar 5, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@dontcallmesherryli dontcallmesherryli added the dependencies Pull requests that update a dependency file label Apr 1, 2021
@peluja1012 peluja1012 added sdh-linked Team:Detection Rule Management Security Detection Rule Management Team Feature:Rule Management Security Solution Detection Rule Management area labels Sep 15, 2021
@peluja1012 peluja1012 added the Theme: simp_prot_mgmt Security Solution Simplified Protection Management Theme label Oct 26, 2021
@peluja1012 peluja1012 added Team:Detection Alerts Security Detection Alerts Area Team and removed Team:Detection Rule Management Security Detection Rule Management Team labels Aug 4, 2022
@yctercero yctercero added Team:Detection Engine Security Solution Detection Engine Area and removed Team:Detection Alerts Security Detection Alerts Area Team labels May 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
consider-next dependencies Pull requests that update a dependency file enhancement New value added to drive a business result Feature:Rule Management Security Solution Detection Rule Management area needs design sdh-linked Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: simp_prot_mgmt Security Solution Simplified Protection Management Theme
Projects
None yet
Development

No branches or pull requests

4 participants