Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Rule Tuning] Increase Detection Rules lookback to prevent missing endpoint events #199

Closed
brokensound77 opened this issue Aug 20, 2020 · 1 comment
Assignees
Labels
Rule: Tuning tweaking or tuning an existing rule v7.9.1

Comments

@brokensound77
Copy link
Contributor

Description

Update rules targeting endpoint data to have a minimum lookback of 3m (or existing lookback + 2m) to prevent misses

@brokensound77
Copy link
Contributor Author

resolved by #200

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rule: Tuning tweaking or tuning an existing rule v7.9.1
Projects
None yet
Development

No branches or pull requests

2 participants