-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Labels
enhancementNew feature or requestNew feature or requestparserParser and fixture coverage workParser and fixture coverage work
Milestone
Description
Summary
- extend sanitized fixture coverage for common Linux auth families beyond current sample patterns
- parse
Accepted publickeysuccess events and selectedpam_faillock/pam_sssfailure variants - keep unsupported lines visible through telemetry rather than silently absorbing them
Scope
- add sanitized syslog and
journalctl_short_fullfixtures - add parser tests for recognized vs telemetry-only behavior
- do not change detector thresholds in this issue
- do not add cross-host correlation, enrichment, or SIEM-like logic
Acceptance Criteria
Accepted publickeyis parsed as a supported auth event- selected
pam_faillockandpam_sssvariants are either parsed explicitly or bucketed deterministically in telemetry - parser coverage metrics remain deterministic
- existing golden report contract tests continue to pass
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestparserParser and fixture coverage workParser and fixture coverage work