Closed Aegrah closed 2 months ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.@Aegrah could you please follow the setup guide template mentioned in this issue: https://github.com/elastic/ia-trade-team/issues/410
@approksiu copy pasted it from the template now.
Summary
Added setup guide instructions to this rule, to allow customers to more easily set up the necessary auditd rules.