Hello,
Just sharing my experience updating Elastic prebuilt Security rules after being away for about 1.5 months.
When I logged back in, I had roughly 1,200 rule updates waiting. That is fine in itself - I clicked Update all and expected the bulk update process to handle it.
However, 36 rules showed conflicts, even though I had never intentionally modified those rules.
For each of those 36 rules, I then had to individually:
-
Open and review the conflict
-
Click Save and accept
-
Click Update rule
-
Deal with the deprecated-rule popup and click Load rules
-
Wait several seconds for the update to complete
-
Repeat the entire process for the next rule
With roughly 10 seconds of clicking/navigation plus around 4 seconds of update time per rule, resolving 36 conflicts easily turns into 15-20 minutes of repetitive manual work.
There are really two issues here.
First, I would like to understand why prebuilt rules that I never modified are being reported as conflicting/modified in the first place. If there is some migration, versioning, or other internal change causing this, the UI should make that clear.
Second, even when conflicts are legitimate, the current workflow does not scale. Human review of a conflict can make sense, but forcing the administrator through the same multi-click update workflow 36 times does not.
It would be much better to have something like:
-
Review all conflicting rules in one workflow
-
Multi-select rules and accept the Elastic version in bulk
-
An "Accept upstream version for all" option where appropriate
-
Clear visibility into exactly what caused each conflict
-
Batch/background processing of accepted updates
-
Removal or consolidation of the deprecated-rule popup during this process
I fully understand that conflicting changes should not simply be overwritten without review. The problem is not the review itself - it is the amount of repetitive UI work required after that decision has been made.
For a product with hundreds or thousands of prebuilt detection rules, this workflow needs to scale better.
Willem






