Closed
Description
Meta Summary
Many of the new Linux rules currently do not leverage all potential indices. While doing performance analysis and tuning, my second goal is to ensure that the rules compatible with other data sources, thus (endgame, auditbeat, auditd_manager) will be added to the rule index list.
Estimated Time to Complete
3 - 5 days, depending on how much time is being spent on it. This meta will be one that can be worked at whenever some additional time is available.
Notes
This round of tuning does not only focus on FP/TP analysis, but also on:
- Compatibility;
- Performance.
Tasklist
### Meta Tasks
- [x] Linux Detection Rules Tuning PR
- [x] Linux Cross-Platform Tuning PR
- [x] Linux Building Block Rules Tuning PR
- [x] Linux Building Block Rules Promotion PR
- [x] Linux Endpoint Rules Tuning PR
- [x] Linux Endpoint Rules Promotion PR
### Pull Requests to Enable Tuning or Add Compatibility
- [ ] https://github.com/elastic/detection-rules/pull/3430
- [ ] https://github.com/elastic/detection-rules/pull/3451
- [ ] https://github.com/elastic/detection-rules/pull/3471
- [ ] https://github.com/elastic/detection-rules/pull/3495
### Linux DR Tuning Pull Requests
- [ ] https://github.com/elastic/detection-rules/pull/3452
- [ ] https://github.com/elastic/detection-rules/pull/3453
- [ ] https://github.com/elastic/detection-rules/pull/3454
- [ ] https://github.com/elastic/detection-rules/pull/3455
- [ ] https://github.com/elastic/detection-rules/pull/3456
- [ ] https://github.com/elastic/detection-rules/pull/3457
- [ ] https://github.com/elastic/detection-rules/pull/3458
- [ ] https://github.com/elastic/detection-rules/pull/3460
- [ ] https://github.com/elastic/detection-rules/pull/3461
- [ ] https://github.com/elastic/detection-rules/pull/3462
- [ ] https://github.com/elastic/detection-rules/pull/3463
- [ ] https://github.com/elastic/detection-rules/pull/3464
- [ ] https://github.com/elastic/detection-rules/pull/3465
- [ ] https://github.com/elastic/detection-rules/pull/3467
### Linux Cross-Platform Tuning Pull Requests
- [ ] https://github.com/elastic/detection-rules/pull/3468
### Linux BBR Tuning & Promotion Pull Requests
- [ ] https://github.com/elastic/detection-rules/pull/3469
- [ ] https://github.com/elastic/detection-rules/pull/3470
- [ ] https://github.com/elastic/detection-rules/pull/3472
### Linux ER Tuning & Promotion Pull Requests
- [ ] https://github.com/elastic/endpoint-rules/pull/3336
- [ ] https://github.com/elastic/endpoint-rules/pull/3337