New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rework of #10768 - PR: Merge macos-sshd ruleset into sshd ruleset #11388
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Description labels should be as compact as possible
Co-authored-by: Nicolás Mariano Koremblum <nmkoremblum@gmail.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Copyright is missing in ruleset/testing/tests/test_features.ini
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Alerts' level should be reviewed, there are many level 0 alerts that seem to be wrong.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Missing test for rules 5763
and 5764
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Missing copyright in ruleset/testing/tests/test_features.ini
file.
Added test for 5719 Changed id of 5765 to 5763
Deleted these rules as they are exactly the same as 5718 and 5719.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There are commented decoders, please remove them.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Former rule 5765's ID was changed to 5763 but its test was not modified.
Done |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM !
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM :)
Description
This PR aims to resolve issues detected under #10768 PR.
The issues resolved are:
Checks and changes
Syntax
Grammar
Semantic
Unit testing
All rules and decoders test.
E2E testing
5.a Logs for new or modified decoder/rules sent to a manager running with this PR ruleset appear in Kibana.
5.b There are not affected or broken visualizations on Kibana.
5.c New or modified items can be seen correctly using APP ruleset navigation.
Elasticsearch Template
Stoppers
Others