You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Detector findings are group of rules that a doc id matches. Since doc level monitor distributed approach guarantees that only one node in one execution of a monitor sees a given doc, a unique finding is guaranteed
But threat intel monitor creates findings per Ioc and links doc ids that contain that ioc. So every single node in distributed execution can create a finding for an ioc and link unique doc ids but since threat intel finding is identified by Ioc value and nto a doc id there would be duplicate findings.
Potential solutions:
use locking mechanism to create finding. if finding exists, then update with doc ids
The text was updated successfully, but these errors were encountered:
Detector findings are group of rules that a doc id matches. Since doc level monitor distributed approach guarantees that only one node in one execution of a monitor sees a given doc, a unique finding is guaranteed
But threat intel monitor creates findings per Ioc and links doc ids that contain that ioc. So every single node in distributed execution can create a finding for an ioc and link unique doc ids but since threat intel finding is identified by Ioc value and nto a doc id there would be duplicate findings.
Potential solutions:
The text was updated successfully, but these errors were encountered: