Monitoring Detection Health
The highly reliable detections that engineering teams create require continuous maintenance and monitoring. As we enter a new phase of our detection-as-code journey, we shift our focus from effective building to effective oversight. Over time, our detections and automations may need to be revised, or at times deprecated, as conditions change within the environment and log sources. The sooner we catch rules that are not performing as expected, the better off the SOC and our other stakeholders will be.
This chapter focuses on determining which mechanisms are best for ensuring our detections stay within operating conditions. We also look for sources of information that can help support our decision-making with metrics. Finally, we take what we have collected for metrics and log sources and explore the logic of how to implement calculated metrics in dashboard form.
By the end of the chapter, you will understand how to measure detection health over time...