-
Notifications
You must be signed in to change notification settings - Fork 133
Open
Labels
Team:ExperienceIssues owned by the Experience Docs TeamIssues owned by the Experience Docs Teamv9.2.0
Description
Description
Users want to be able to refine indicator match rules statement with "DOES NOT MATCH" condition.
Example:
This match will occur when there is a list of users mapped to geographic regions in an indicator index. If the username matches in the logs but the geographic region does not match then a detection should fire. index1.username == indicator_index.username AND index1.geo.city != indicator_index.city
Resources
PR: elastic/kibana#227084
Issue: https://github.com/elastic/security-team/issues/13022
Which documentation set does this change impact?
Elastic On-Prem and Cloud (all)
Feature differences
N/A
What release is this request related to?
9.2
Serverless release
When merged and docs ready
Collaboration model
The documentation team
Point of contact.
Main contact: @vitaliidm
Stakeholders: @yctercero @approksiu
Metadata
Metadata
Assignees
Labels
Team:ExperienceIssues owned by the Experience Docs TeamIssues owned by the Experience Docs Teamv9.2.0