Skip to content

[Meta] Linux Tuning & Index Pattern Checks #3428

Closed
@Aegrah

Description

@Aegrah

Meta Summary

Many of the new Linux rules currently do not leverage all potential indices. While doing performance analysis and tuning, my second goal is to ensure that the rules compatible with other data sources, thus (endgame, auditbeat, auditd_manager) will be added to the rule index list.

Estimated Time to Complete

3 - 5 days, depending on how much time is being spent on it. This meta will be one that can be worked at whenever some additional time is available.

Notes

This round of tuning does not only focus on FP/TP analysis, but also on:

  • Compatibility;
  • Performance.

Tasklist

### Meta Tasks
- [x] Linux Detection Rules Tuning PR
- [x] Linux Cross-Platform Tuning PR
- [x] Linux Building Block Rules Tuning PR
- [x] Linux Building Block Rules Promotion PR
- [x] Linux Endpoint Rules Tuning PR
- [x] Linux Endpoint Rules Promotion PR
### Pull Requests to Enable Tuning or Add Compatibility
- [ ] https://github.com/elastic/detection-rules/pull/3430
- [ ] https://github.com/elastic/detection-rules/pull/3451
- [ ] https://github.com/elastic/detection-rules/pull/3471
- [ ] https://github.com/elastic/detection-rules/pull/3495
### Linux DR Tuning Pull Requests
- [ ] https://github.com/elastic/detection-rules/pull/3452
- [ ] https://github.com/elastic/detection-rules/pull/3453
- [ ] https://github.com/elastic/detection-rules/pull/3454
- [ ] https://github.com/elastic/detection-rules/pull/3455
- [ ] https://github.com/elastic/detection-rules/pull/3456
- [ ] https://github.com/elastic/detection-rules/pull/3457
- [ ] https://github.com/elastic/detection-rules/pull/3458
- [ ] https://github.com/elastic/detection-rules/pull/3460
- [ ] https://github.com/elastic/detection-rules/pull/3461
- [ ] https://github.com/elastic/detection-rules/pull/3462
- [ ] https://github.com/elastic/detection-rules/pull/3463
- [ ] https://github.com/elastic/detection-rules/pull/3464
- [ ] https://github.com/elastic/detection-rules/pull/3465
- [ ] https://github.com/elastic/detection-rules/pull/3467
### Linux Cross-Platform Tuning Pull Requests
- [ ] https://github.com/elastic/detection-rules/pull/3468
### Linux BBR Tuning & Promotion Pull Requests
- [ ] https://github.com/elastic/detection-rules/pull/3469
- [ ] https://github.com/elastic/detection-rules/pull/3470
- [ ] https://github.com/elastic/detection-rules/pull/3472
### Linux ER Tuning & Promotion Pull Requests
- [ ] https://github.com/elastic/endpoint-rules/pull/3336
- [ ] https://github.com/elastic/endpoint-rules/pull/3337

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions