Closed shashank-elastic closed 3 weeks ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.
Pull Request
Issue link(s): Missed an update in PR https://github.com/elastic/detection-rules/pull/4079
Summary - What I changed
Updates these rules with a min_stack condition to 8.13 to avoid double bumps in the version lock.
How To Test
Checklist
bug
,enhancement
,schema
,Rule: New
,Rule: Deprecation
,Rule: Tuning
,Hunt: New
, orHunt: Tuning
so guidelines can be generatedmeta:rapid-merge
label if planning to merge within 24 hoursContributor checklist