Actions
Task #6463
openeve/output: investigate how to track coverage / parity
Description
We want to find a reliable and efficient way to track the outputs that we have on eve, to ensure they're
consistent and that we have everything represented in our JSON schema.
Updated by Juliana Fajardini Reichow about 1 year ago
- Related to Task #6443: Suricon 2023 brainstorm added
Updated by Juliana Fajardini Reichow about 1 year ago
- Subject changed from outputs: investigate how to track coverage / parity to eve/output: investigate how to track coverage / parity
This also relates to ensuring that for each protocol, there are no logging discrepancies when we log a field in an alert and in an event, for instance.
Updated by Victor Julien about 1 year ago
- Related to Documentation #6478: schema: add missing fields added
Updated by Juliana Fajardini Reichow about 1 year ago
- Related to Task #4772: tracking: parity between fields logged and fields available for detection added
Updated by Juliana Fajardini Reichow 3 months ago
- Blocks Story #6597: rules: improve rules keyword/output parity added
Actions