[Security][9.4 & Serverless][DE]: Adds docs for the gaps reason UI and error status#5865
[Security][9.4 & Serverless][DE]: Adds docs for the gaps reason UI and error status#5865nastasha-solomon wants to merge 10 commits intomainfrom
error status#5865Conversation
🔍 Preview links for changed docs |
✅ Vale Linting ResultsNo issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
mdbirnstiehl
left a comment
There was a problem hiding this comment.
LGTM overall! I added a couple of suggestions for your consideration.
| | Unfilled gaps duration | Total duration of remaining unfilled or partially filled gaps. The total can change based on the time range you select (data on gaps older than 90 days is not retained). If a rule has no gaps, the column displays a dash (`––`). | | ||
| | Gap fill status | {applies_to}`stack: ga 9.3+` Shows whether unfilled gaps remain, a gap-fill run is in progress, every gap is filled, and more. Refer to the [Gap status](#gap-status) table for the available statuses. | | ||
|
|
||
| #### Gap status [gap-status] |
There was a problem hiding this comment.
Would it make sense to have this as Gap fill status to match the language in the UI and in this docs section?
| | Column | Description | | ||
| |--------|-------------| | ||
| | Last Gap (if any) | How long the most recent gap lasted. | | ||
| | Unfilled gaps duration | Total duration of remaining unfilled or partially filled gaps. The total can change based on the time range you select (data on gaps older than 90 days is not retained). If a rule has no gaps, the column displays a dash (`––`). | | ||
| | Gap fill status | {applies_to}`stack: ga 9.3+` Shows whether unfilled gaps remain, a gap-fill run is in progress, every gap is filled, and more. Refer to the [Gap status](#gap-status) table for the available statuses. | |
There was a problem hiding this comment.
From what I see in the UI, the columns are organized as Gap fill status, Last gap, Unfilled gaps duration. Might be good to match that ordering in the table for scanability?
|
|
||
| These values appear in the **Reason** column on the **Execution results** tab (and in related filters). They also drive which gaps are included in the **Rules with gaps** overview and in automatic gap fill. | ||
|
|
||
| The gap detection scope applies to the whole {{kib}} space. Use it to include or exclude gaps that occurred while a rule was turned off. By default, those gaps are excluded from the overview and from automatic gap fill because they often reflect planned maintenance rather than an unexpected detection failure. |
There was a problem hiding this comment.
| The gap detection scope applies to the whole {{kib}} space. Use it to include or exclude gaps that occurred while a rule was turned off. By default, those gaps are excluded from the overview and from automatic gap fill because they often reflect planned maintenance rather than an unexpected detection failure. | |
| The **Gap detection scope** applies to the whole {{kib}} space. Use it to include or exclude gaps that occurred while a rule was turned off. By default, those gaps are excluded from the overview and from automatic gap fill because they often reflect planned maintenance rather than an unexpected detection failure. |
Just noticed this is how it's formatted in the list above and in the note below.
Summary
Fixes #5789 and #5747 by adding docs for the gaps reason UI and
errorstatus.Previews
Generative AI disclosure
Cursor + Composer