metron-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From cestella <>
Subject [GitHub] incubator-metron pull request #426: METRON-675: Make Threat Triage rules abl...
Date Thu, 26 Jan 2017 16:33:28 GMT
GitHub user cestella opened a pull request:

    METRON-675: Make Threat Triage rules able to be assigned names and comments

    There may be many, many threat triage rules. To help organize these, we should make them
slightly more complex than a simple key/value as we have it now. We should add optional name
and optional comment fields.
    This essentially makes the risk level rules slightly more complex.  The format goes from:
    "riskLevelRules" : {
      "stellar expression" : numeric score
    "riskLevelRules" : [
         "name" : "optional name",
         "comment" : "optional comment",
         "rule" : "stellar expression",
         "score" : numeric score
    This is NOT backwards compatible, but I think it's more explicit and a bit more clear.
    Testing plan to come in a follow-on comment.

You can merge this pull request into a Git repository by running:

    $ git pull METRON-675

Alternatively you can review and apply these changes as the patch at:

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

    This closes #426
commit 2d9c129e2be95d635d5c014415087b7a13a678db
Author: cstella <>
Date:   2017-01-26T16:15:01Z

    METRON-675: Add name and description to threat triage rules.

commit 8639d9967afb2add2035aa57fa60d4cc17cbb117
Author: cstella <>
Date:   2017-01-26T16:21:34Z

    forgot license


If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at or file a JIRA ticket
with INFRA.

View raw message