FEATURE/DOCUMENTATION: Improve Playbook filtering documentation #12705
Replies: 1 comment
-
@TOoSmOotH Mike, discussions is becoming (quite often) the place where legitimate issues go to die. This is not a discussion, it is an issue/feature request, and should be tracked as such. I will be filing it again as such. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
The documentation for configuring Playbook -alert- filters is sorely lacking.
For instance, valuable documentation missing includes:
There are many playbook rules that remain inactive by default that are quite useful in real-world setups, but need fine tuning due to false positives, for example in container environments. The documentation currently has no real content about configuration of said filters, and the publicly available information is also deficient. This most likely results in people just deactivating the problematic rules.... a zero-sum game.
Beta Was this translation helpful? Give feedback.
All reactions