No description
Find a file
Madison Caldwell bdf7b88b45
[Security Solution][Detections] Handle dupes when processing threshold rules (#83062)
* Fix threshold rule synthetic signal generation

* Use top_hits aggregation

* Find signals and aggregate over search terms

* Exclude dupes

* Fixes to algorithm

* Sync timestamps with events/signals

* Add timestampOverride

* Revert changes in signal creation

* Simplify query, return 10k buckets

* Account for when threshold.field is not supplied

* Ensure we're getting the last event when threshold.field is not provided

* Add missing import

* Handle case where threshold field not supplied

* Fix type errors

* Handle non-ECS fields

* Regorganize

* Address comments

* Fix type error

* Add unit test for buildBulkBody on threshold results

* Add threshold_count back to mapping (and deprecate)

* Timestamp fixes

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
2020-11-29 22:10:23 -05:00
.ci chore(NA): enable yarn prefer offline and local mirror for development (#84124) 2020-11-25 00:18:18 +00:00
.github Changes code ownership from kibana-telemetry to kibana-core (#84281) 2020-11-24 16:32:46 -07:00
.teamcity [CI] Initial TeamCity implementation (#81043) 2020-11-20 14:32:53 -05:00
common/graphql
config [deb/rpm] Remove /var prefix from tmpfiles.d (#82196) 2020-11-09 10:05:26 -06:00
data
docs fix identation in list (#84301) 2020-11-26 12:08:47 +01:00
examples [DX] Prettier v2.2 (#83899) 2020-11-23 13:17:05 +01:00
licenses
packages [dev/cli] detect worker type using env, not cluster module (#83977) 2020-11-25 08:03:47 -07:00
plugins
rfcs Use .kibana instead of .kibana_current to mark migration completion (#83373) 2020-11-25 15:20:56 +01:00
scripts [cli] Add bin/kibana-encryption-keys (#82838) 2020-11-19 12:41:48 -06:00
src Improve short-url redirect validation (#84366) 2020-11-26 10:51:10 -05:00
tasks
test skip flaky suite (#84445) 2020-11-27 15:14:42 +00:00
typings
utilities
vars chore(NA): enable yarn prefer offline and local mirror for development (#84124) 2020-11-25 00:18:18 +00:00
x-pack [Security Solution][Detections] Handle dupes when processing threshold rules (#83062) 2020-11-29 22:10:23 -05:00
.backportrc.json
.browserslistrc
.editorconfig
.eslintignore
.eslintrc.js Update typescript eslint to v4.8 (#83520) 2020-11-18 18:23:08 +01:00
.fossa.yml
.gitattributes
.gitignore chore(NA): enable yarn prefer offline and local mirror for development (#84124) 2020-11-25 00:18:18 +00:00
.i18nrc.json [Visualize] New visualization wizard (#79627) 2020-11-06 18:03:44 +02:00
.node-version Bump Node.js from 12.19.0 to 12.19.1 (#83452) 2020-11-17 09:41:35 +01:00
.nvmrc Bump Node.js from 12.19.0 to 12.19.1 (#83452) 2020-11-17 09:41:35 +01:00
.prettierrc
.sass-lint.yml [Visualize] New visualization wizard (#79627) 2020-11-06 18:03:44 +02:00
.telemetryrc.json
.yarnrc chore(NA): enable yarn prefer offline and local mirror for development (#84124) 2020-11-25 00:18:18 +00:00
api-documenter.json
CONTRIBUTING.md
FAQ.md
github_checks_reporter.json
Gruntfile.js
Jenkinsfile chore(NA): remove usage of unverified es snapshots (#83589) 2020-11-18 00:18:31 +00:00
kibana.d.ts
LICENSE.txt
NOTICE.txt
package.json [Security Solution] Cleanup graphiql (#82595) 2020-11-25 10:45:32 +01:00
preinstall_check.js
README.md Fix "Getting started" link in README (#84153) 2020-11-23 15:33:02 -05:00
renovate.json5
STYLEGUIDE.md
tsconfig.base.json Update typescript eslint to v4.8 (#83520) 2020-11-18 18:23:08 +01:00
tsconfig.browser.json
tsconfig.json list all the refs in tsconfig.json (#83678) 2020-11-20 08:19:08 +01:00
tsconfig.refs.json
tsconfig.types.json
TYPESCRIPT.md
yarn.lock Upgrade fp-ts to 2.8.6 (#83866) 2020-11-26 20:34:06 +01:00

Kibana

Kibana is your window into the Elastic Stack. Specifically, it's a browser-based analytics and search dashboard for Elasticsearch.

Getting Started

If you just want to try Kibana out, check out the Elastic Stack Getting Started Page to give it a whirl.

If you're interested in diving a bit deeper and getting a taste of Kibana's capabilities, head over to the Kibana Getting Started Page.

Using a Kibana Release

If you want to use a Kibana release in production, give it a test run, or just play around:

Building and Running Kibana, and/or Contributing Code

You might want to build Kibana locally to contribute some code, test out the latest features, or try out an open PR:

Documentation

Visit Elastic.co for the full Kibana documentation.

For information about building the documentation, see the README in elastic/docs.

Version Compatibility with Elasticsearch

Ideally, you should be running Elasticsearch and Kibana with matching version numbers. If your Elasticsearch has an older version number or a newer major number than Kibana, then Kibana will fail to run. If Elasticsearch has a newer minor or patch number than Kibana, then the Kibana Server will log a warning.

Note: The version numbers below are only examples, meant to illustrate the relationships between different types of version numbers.

Situation Example Kibana version Example ES version Outcome
Versions are the same. 5.1.2 5.1.2 💚 OK
ES patch number is newer. 5.1.2 5.1.5 ⚠️ Logged warning
ES minor number is newer. 5.1.2 5.5.0 ⚠️ Logged warning
ES major number is newer. 5.1.2 6.0.0 🚫 Fatal error
ES patch number is older. 5.1.2 5.1.0 ⚠️ Logged warning
ES minor number is older. 5.1.2 5.0.0 🚫 Fatal error
ES major number is older. 5.1.2 4.0.0 🚫 Fatal error

Questions? Problems? Suggestions?

  • If you've found a bug or want to request a feature, please create a GitHub Issue. Please check to make sure someone else hasn't already created an issue for the same topic.
  • Need help using Kibana? Ask away on our Kibana Discuss Forum and a fellow community member or Elastic engineer will be glad to help you out.