49 results found
-
PPL & Observability SIEM features in OpenSearch
As a Security Analyst,
I want to utilise the Observability plugin & PPL in an efficient manner. Features such as tooltips and autocomplete would help a lot, as well as bug fixes and regular updates.
The syntax is not well nor widely understood, and there are lingering bugs, which for a user are very hard to duplicate across the microcosm of repositories which bundle into the suite.
Observabilitiy & PPL feels like a very promising place for OpenSearch to become more useful to a security operations team, where currently the capabilities are extremely limiting.
While OpenSearch Dashboards, with tenancy and…
2 votes -
Make OpenSearch Dashboards session timeout configurable
As a developer
I would like to have the following configuration options exposed:opensearch_security.cookie.ttl
opensearch_security.session.ttl
opensearch_security.session.keepaliveso that I can lengthen the dashboard session timeout for my users.
3 votes -
One-click visualisation creation from Discover in OpenSearch
As a security analyst,
I want to create a visualisation from a search, which can then be added to an existing or new dashboard, so that I can save time creating dashboard elements and create dashboard elements in a much easier manner than is currently possible.
2 votes -
Compliance dashboards for OpenSearch
As a security operator,
I want to have a view of our compliance status across various data sources, in a 'continual assurance' manner. e.g. PCI, SOC2, ISO27001, or frameworks such as NIST CSF. So that I can get a continual view of degredations as they occur.
so that I can [describe the benefit or a problem you want to solve]
In addition, [share any additional context or why this idea is important to you]2 votes -
API integration for cloud event sources
As a security analyst,
I want to collect events directly from cloud resources (XaaS, eg AWS, Azure, Okta, Github, GCP...) without having to run an intermediary host such as Logstash, so that I can lower my infrastructure cost, lower external hosting complexity and lower our maintenance overhead.
2 votes -
Correlation between indexes in OpenSearch Dashboards
As a security analyst,
I want to be able to search across more than one index within Discover (and Dashboards queries), so that I can enrich data between sources.
For example, Okta logs contain an organisations user logins, along with their IP addresses. We may also have SSHd logs, and between the two we could correlate IP address to provide user details into a search of SSH logs. Many examples could be found.
In addition, [share any additional context or why this idea is important to you]2 votes -
The ability to Reduce logs in OpenSearch
As a security analyst,
I want to 'reduce' the logs searched to reduce the data to common patterns, allowing me to easily see meaningful events.
1 vote -
Add the ability to remove 'count' column in Table visualisations in OpenSearch
As a security analyst,
I want to remove the 'count' column in Table visualisation, so that the data irrelevant to what we need is not displayed.
1 voteI will raise an upstream ticket on this
-
A unified search, alarm & dashboarding experience in OpenSearch
As a security analyst,
I want to have a unified alerting, dashboarding and search experience in my SIEM, so that our capabilities are not spread across multiple plugins with differing query languages.
Currently between Dashboards/Discover, Security Analytics, Observability there is not a unified experience, it is extremely confusing and difficult to use, and to make this harder each component has a different set of upstream repositories and seemingly little co-ordination between them in features, documentation and bug fixes, making the experience very confusing and difficult.
2 votes -
Save comments in OpenSearch searches
As a security analyst,
I want to add comments into my searches within Discover, so that we have a shared history and understanding of what the intention of a search or part thereof is for.
1 vote -
Search a string as another data type in OpenSearch
As a security or data analyst,
I want to be able to treat a string as another data type at search, for example searching the string "1" as an integer upon search, so that I can search data appropriately without having to update the mapping and reindex all data.
2 votes -
OpenSearch Dashboards range pickers in Visualisations
As a security analyst,
I want to utilise 'range' in visualisations without having to Edit Query as DSL,
so that I can save time and also have people without extensive DSL knowledge create visualisations.2 votes -
Professional or Customer Support for OpenSearch Use
As a security analyst or operator,
I want to have support in using OpenSearch effectively for my use-case, so that I can have success in using this (complex, confusing, disparate) system as a SIEM without expending countless hours in trying to troubleshoot or effectively utilise the tool.
1 vote -
Keep OpenSearch Security Plugin SIGMA rules up to date.
As a security analyst and operator,
I want to utilise up-to-date SIGMA rules in the OpenSearch Security Plugin, so that I can utilise current contributions from the opensource community.
For example - at the time of writing this - the Okta rules in Security Plugin repo (main branch) have not been updated since February 2023 - with 13 rules available , while the SIGMA repo (master branch) Okta rules were last updated in December 2023 - with 21 rules available, notably including rules based on the high-profile Okta breach in 2023.
This can be observed across many rule categories, with…
2 votes -
View the underlying data of a visualisations in OpenSearch Dashboard
As an OpenSearch user
I want to view the data underneath the visualisation
so that I can quickly identify root cause of some abnormal behaviour of my system2 votes -
Inability to extract fields upon search
As a database admin
I want to define field patterns at search
so that I can effectively work with new field pattern3 votes -
Internal data table/lookup functionality
As a database admin
I want to have queries run upon a schedule and populate internal data tables
so that I can enrich the search and alerting functionality3 votes -
filter by backend cluster setting
As an application developer
I want to add an advanced configuration for cluster setting 'plugins.alerting.filterbybackend_roles'
so that I can prevent users from different tenants from seeing each other's monitorsCurrently unable to implement the following due to the current limitation: https://opensearch.org/docs/latest/observing-your-data/alerting/security/
1 voteThis is currently an advanced configuration for Security Plugin on OpenSearch upstream, we are evaluating this idea will comeback to this later on this quarter. This idea is valid and put it in Gathering Interest state now in a meantime
-
Allow changing of OpenSearch configurable limits
As a customer
I want to change the configurable limits in OpenSearch
so that I can change things like https://opensearch.org/docs/latest/install-and-configure/configuring-opensearch/circuit-breaker/ when doing one-off large operations like deleting a bulk amount of data1 vote -
Performance Insights for OpenSearch
As an OpenSearch administrator I would like to see performance statistics and possibly root cause analysis for any performance issues. OpenSearch project has Performance Analyzer plugin as well as root cause analysis framework for performance optimisation.
https://opensearch.org/docs/latest/monitoring-your-cluster/pa/index/
https://opensearch.org/docs/latest/monitoring-your-cluster/pa/rca/index/1 vote
- Don't see your idea?