Skip to content

Conversation

@shashank-elastic
Copy link
Contributor

Summary

Issue link(s): Rule was soaked a BBR with no feedback data to tune, the rule now has compatibility issues with lates integration and stack versions, as seen in PR. With no usage there is additional overhead to maintian this rule, hence deprecating this

How To Test

  • Unit test should pass

Checklist

  • Added a label for the type of pr: bug, enhancement, schema, maintenance, Rule: New, Rule: Deprecation, Rule: Tuning, Hunt: New, or Hunt: Tuning so guidelines can be generated
  • Added the meta:rapid-merge label if planning to merge within 24 hours
  • Secret and sensitive material has been managed correctly
  • Automated testing was updated or added to match the most common scenarios
  • Documentation and comments were added for features that require explanation

Contributor checklist

@github-actions
Copy link
Contributor

github-actions bot commented Mar 4, 2025

Rule: Deprecation - Guidelines

These guidelines serve as a reminder set of considerations when recommending the deprecation of a rule.

Documentation and Context

  • Description of the reason for deprecation.
  • Include any context or historical data supporting the deprecation decision.

Rule Metadata Checks

  • deprecated = true added to the rule metadata.
  • updated_date should be the date of the PR.

Testing and Validation

  • A prior rule tuning occurred for the rule where Deprecated - is prepended to the rule name, and the rule has already been released.
  • Rule has be moved to the _deprecated directory.
  • Double check gaps potentially or inadvertently introduced.
  • Provide evidence that the rule is no longer needed or has been replaced (e.g., alternative rules, updated detection methods).

@tradebot-elastic
Copy link

tradebot-elastic commented Mar 4, 2025

⛔️ Tests failed:

  • ❌ Potential Cross Site Scripting (XSS) (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
    • events_validation_missing: Not tested with events

@shashank-elastic shashank-elastic merged commit 467034e into main Mar 4, 2025
23 checks passed
@shashank-elastic shashank-elastic deleted the deprecate_bbr branch March 4, 2025 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants