[ResponseOps] Write rule execution results to Event Log #135209
Labels
Feature:Alerting/RulesFramework
Issues related to the Alerting Rules Framework
Feature:Rule Monitoring
Security Solution Detection Rule Monitoring area
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Related to: #135127
Summary
When #135127 is implemented and Security Solution rules start passing execution outcomes and custom metrics to the Alerting Framework, we would like the Framework to start writing "rule execution result" events to Event Log.
We could then query these events in Security Solution to:
Example
Here's an example of what this rule execution result event might look like:
Example of Security Solution events
There are two types of events that we currently write to Event Log on the Security Solution side that we would get rid of when this issue is addressed:
status-change
andexecution-metrics
.The text was updated successfully, but these errors were encountered: