Skip to content

Draft review index: technology-specific v11 filter and rule fixes - #2589

Closed
rvald26 wants to merge 1 commit into
utmstack:v11from
rvald26:codex/filter-dictionary-audit
Closed

rvald26 wants to merge 1 commit into
utmstack:v11from
rvald26:codex/filter-dictionary-audit

Conversation

@rvald26

@rvald26 rvald26 commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Technology draft PR review index

This combined draft is superseded for review by the separate technology drafts below. Leave this aggregate PR as a reference; do not merge it. The new drafts contain additional producer/consumer checks and corrections identified while splitting the audit.

All 34 new PRs target the actual utmstack/UTMStack repository, base v11. There are 33 technology-specific drafts plus the shared alerts-platform draft. Every new PR was verified OPEN and DRAFT with auto-merge disabled; production files in each technology diff belong only to that technology. No PR was merged or deployed.

Shared alerts dependency

fix(alerts): resolve lastEvent grouping and add scoped filter contracts provides lastEvent.* grouping resolution and the reusable test runner. Apply it before relying on the technology manifests to execute under go test. Technology PR bodies identify those that also need its runtime grouping fix.

Review separately

Technology Draft PR Filter changes Rule changes Cases
Bitdefender GravityZone #2591 1 7 8
Deceptive Bytes #2592 1 0 5
ESET #2593 1 1 2
Kaspersky #2594 1 14 2
SentinelOne #2595 1 0 3
AWS #2596 1 0 2
Azure Event Hub #2597 1 0 11
Cisco ASA #2598 1 0 12
Cisco Switch #2599 1 0 5
Cisco Firepower #2600 1 0 12
Cisco Meraki #2601 1 1 6
CrowdStrike #2602 1 8 2
FortiGate #2603 1 0 6
FortiWeb #2604 1 1 2
Generic Input #2605 1 0 1
GitHub #2606 1 0 2
Google Cloud #2607 1 2 13
IBM AIX #2608 1 0 2
IBM i / AS400 #2609 1 0 2
Linux #2610 1 23 3
MikroTik #2611 1 1 3
NetFlow #2612 1 4 6
Microsoft 365 #2613 1 6 14
Palo Alto Networks #2614 1 0 4
pfSense #2615 1 0 2
SonicWall #2616 1 0 3
Sophos #2617 2 0 7
Suricata #2618 1 3 18
Generic Syslog #2619 1 0 1
VMware ESXi #2620 1 14 1
Windows #2621 1 15 8
macOS #2622 0 1 2
JSON Input #2623 0 1 1

Verification and limits

  • Each technology branch independently passed its scoped tests with the shared runner temporarily applied, plus git diff --check.
  • The unpublished local integration passed 671 filter/rule contract subtests (all 36 filters and 635 rules), 172 synthetic normalization cases (171 technology cases plus a core smoke case), and alert-grouping unit tests.
  • Checks use the actual pinned go-sdk v1.1.31 descriptors, YAML decoder, CEL implementation and final Event conversion. Both supplied UTMStack data dictionaries and the filter/rule wiki informed the review. Documented aliases, custom log fields and supported numeric strings were preserved.
  • Split verification corrected severity classification before Deceptive Bytes cleanup; retained NetFlow counters consumed by four rules; preserved Meraki event/message fields, accepted retrospective AMP events without inventing an IP and excluded IDS events from AMP detection; and scoped macOS history to the agent dataSource identity.
  • Normalization tests start from synthetic extraction results. Raw-log extraction through the closed EventProcessor, dynamic enrichment and OpenSearch historical alert generation remain staging work. No reduction in customer TI alert volume has been measured.
  • JSON Input's narrow grouping-name fix still requires upstream/custom normalization to supply the standard origin.ip needed by its existing trigger. The draft documents this producer requirement explicitly. macOS requires the documented per-host agent dataSource; missing/unknown identity is rejected.
  • Existing custom rules that consume legacy actionResult/severity spellings need rollout review.

The original combined audit remains in this PR's diff for reference. Review and approval should happen on the individual drafts above.

GitHub checks

Local checks passed. GitHub AI-review jobs are failing before performing review because
THREATWINDS_API_KEY is unavailable in these fork-triggered workflows. This was confirmed
in the shared-alerts, FortiGate and Sophos job logs; it is a CI configuration limitation,
not an AI review finding. Go dependency checks are separate and were passing or still
running at the verification snapshot. See each draft for its current check status.

This was referenced Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant