Skip to content

Improve detection data source health gates#1941

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/detection-data-source-health-1578
Open

Improve detection data source health gates#1941
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/detection-data-source-health-1578

Conversation

@DENGXUELIN
Copy link
Copy Markdown

Summary

  • add an additive data-source health and telemetry drift gate inside the existing detection-engineering workflow
  • require ingestion freshness, expected event volume, parser/schema compatibility, required field coverage, collector health, and replay/canary proof before calling coverage operational
  • add vulnerable and benign fixtures for stale parser zero-match coverage versus current telemetry with replay/schema evidence

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check
  • Added-line ASCII check
  • Content marker check for data source health, telemetry drift, ingestion freshness, expected volume, parser/schema, required fields, replay/canary, and zero-match evidence
  • git merge-tree --write-tree origin/main HEAD

Closes #1578

Bounty request: Improver Moderate / USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] detection-engineering: add data-source health and telemetry drift evidence gates

1 participant