Skip to content

[FR] CLI function to check a cluster for Deprecated Rules #4553

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
w0rk3r opened this issue Mar 20, 2025 · 1 comment
Open

[FR] CLI function to check a cluster for Deprecated Rules #4553

w0rk3r opened this issue Mar 20, 2025 · 1 comment
Labels
enhancement New feature or request Team: TRADE

Comments

@w0rk3r
Copy link
Contributor

w0rk3r commented Mar 20, 2025

Repository Feature

Core Repo - (rule management, validation, testing, lib, cicd, etc.)

Problem Description

Long-time customers might still be running deprecated rules without realizing that the logic is either not performant or flawed.

Desired Solution

We could provide a CLI command to check the cluster for rules that are in https://github.com/elastic/detection-rules/blob/main/detection_rules/etc/deprecated_rules.json

Here is a quick (and dirty) check in python I did for a customer: https://gist.github.com/w0rk3r/01196baf3449d4f1605337aa497c0e7a

Considered Alternatives

No response

Additional Context

@w0rk3r w0rk3r added enhancement New feature or request Team: TRADE labels Mar 20, 2025
@richlv
Copy link

richlv commented Apr 21, 2025

Somewhat related to #2327 .

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Team: TRADE
Projects
None yet
Development

No branches or pull requests

2 participants