Skip to content

Commit 66a20e3

Browse files
committed
cre datasource consolidation
1 parent 8c8b5bf commit 66a20e3

File tree

12 files changed

+13
-13
lines changed

12 files changed

+13
-13
lines changed

rules/cre-2025-0034/datadog-agent-disabled-due-to.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,6 @@ rules:
4040
rule:
4141
set:
4242
event:
43-
source: cre.log.datadog
43+
source: cre.log.datadog.agent
4444
match:
4545
- regex: .*DD_API_KEY undefined\. Metrics, logs and events will not be reported to DataDog.*

rules/cre-2025-0059/dd-cws-instrumentation-webhook-fails.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ rules:
4343
rule:
4444
set:
4545
event:
46-
source: cre.log.datadog
46+
source: cre.log.datadog.agent
4747
match:
4848
- regex: 'failed to register CWS Instrumentation webhook.*cluster_agent\.service_account_name'
4949

rules/cre-2025-0060/dd-openmetrics-scrape-404.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,6 @@ rules:
3737
rule:
3838
set:
3939
event:
40-
source: cre.log.datadog
40+
source: cre.log.datadog.agent
4141
match:
4242
- regex: "Error running check:.*http://[0-9.]+:7801/metrics: 404 Client Error: Not Found for url: http://[0-9.]+:7801/metrics"

rules/cre-2025-0069/kubernetes-fsgroup-nfs-ignored.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ rules:
4949
set:
5050
window: 5s
5151
event:
52-
source: cre.k8s.manifest
52+
source: cre.prequel.kubernetes.resource.persistentvolumes.v1
5353
match:
5454
- jq: '.kind == "PersistentVolume" and (.spec.nfs != null)'
5555
- jq: >

rules/cre-2025-0071/coredns-unavailable-dns-outage.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,6 @@ rules:
5353
rule:
5454
set:
5555
event:
56-
source: cre.log.kubernetes
56+
source: cre.kubernetes
5757
match:
5858
- regex: "Scaled down replica set coredns-.+ from [1-9]+ to 0|Stopping container coredns|Readiness probe failed.+connection refused"

rules/cre-2025-0099/redpanda-memory-startup-crash.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ rules:
6161
sequence:
6262
window: "120s"
6363
event:
64-
source: application-logs
64+
source: cre.log.redpanda
6565
origin: true
6666
order:
6767
- permission_failures

rules/cre-2025-0119/kubernetes-pdb-violation.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,7 @@ rules:
8080
rule:
8181
set:
8282
event:
83-
source: cre.log.kubernetes
83+
source: cre.kubernetes
8484
window: 5m
8585
match:
8686
- regex: "Warning\\s+PodDisruptionBudgetViolation.+Pod disruption budget violation detected: maxUnavailable: \\d+ conflicts with minAvailable: \\d+"
@@ -92,7 +92,7 @@ rules:
9292
sequence:
9393
window: 10m
9494
event:
95-
source: cre.log.kubernetes
95+
source: cre.kubernetes
9696
order:
9797
- regex: "Normal\\s+ScalingReplicaSet.+Scaled up replica set.+"
9898
- regex: "Warning\\s+PodDisruptionBudgetViolation.+"

rules/cre-2025-0125/k8s-troubleshoot.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ rules:
4545
set:
4646
window: 180s
4747
event:
48-
source: cre.log.kubernetes
48+
source: cre.kubernetes
4949
match:
5050
- regex: 'Evented PLEG:.*DeadlineExceeded'
5151
- regex: 'panic: send on closed channel'

rules/cre-2025-0127/cre-exit-127.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,6 @@ rules:
3939
rule:
4040
set:
4141
event:
42-
source: cre.log.k8s
42+
source: cre.kubernetes
4343
match:
4444
- regex: "^[^\\t]+\\t[^\\t/]+/[^\\t]+\\t[^\\t]+\\t[^\\t]*\\t127$"

rules/cre-2025-0134/cre-exit-134.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,6 @@ rules:
3939
rule:
4040
set:
4141
event:
42-
source: cre.log.k8s
42+
source: cre.kubernetes
4343
match:
4444
- regex: "^[^\\t]+\\t[^\\t/]+/[^\\t]+\\t[^\\t]+\\t[^\\t]*\\t134$"

0 commit comments

Comments
 (0)