Add detection telemetry health fixtures#2139
Open
DENGXUELIN wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/claim #1417
What changed
Adds fixture-backed telemetry readiness and deployed rule-health gates to
detection-engineering.DET-HEALTH-01throughDET-HEALTH-08for ATT&CK data component/logsource mapping, collector health, parser field mapping, deployed SIEM rule status, suppression scope, validation samples, retention, and explicit coverage decision.Why this PR
Existing PR #1418 is a useful Markdown edge-case implementation. This PR is intentionally fixture-backed with rule-health export style JSON so future reviews can distinguish live operational coverage from source-control-only or broken telemetry claims.
Validation
git diff --check origin/main...HEADgit merge-tree --write-tree origin/main HEADdetection-engineering/SKILL.mdversion: 1.0.1,Telemetry Readiness and Rule Health Evidence,DET-HEALTH-01throughDET-HEALTH-08,Telemetry and Rule Health Matrix,Not Evaluable,Parser Fields Proven, andCounting Rules Without Live Telemetry or Rule Healthexpected_skill_decision,telemetry_health,parser_mapping,rule_deployment,suppression_scope,validation_samples,retention, andcoverage_decisionBounty tier
Requesting Improver Moderate ($100) if accepted. This adds structured local fixtures in addition to the telemetry readiness guidance requested by the issue.