Adjust CR Schedules and Lookbacks #1417
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Background
Correlation rules that run too frequently are very cost-ineffective. This PR defaults all managed CRs to running once per day and looking back over the past 36 hours (while respecting the relative time constraints between events using
WithinTimeFrameMinutes
.Changes
RateMinutes
to 1440 (24 hours)LookbackWindowMinutes
to 2160 (36 hours) to allow for log latencyWithinTimeFrameMinutes
to transitions to preserve the original lookback windowTesting
make test
pat validate