elastic / detection-rules

Home Page:https://www.elastic.co/guide/en/security/current/detection-engine-overview.html

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[Rule Tuning] Review all rules for performance optimizations

brokensound77 opened this issue · comments

related to https://github.com/elastic/ia-trade-team/issues/232

It is always good to regularly check in on the state of overall rule performance to ensure that they are as optimized as possible. This means not only reviewing for best practices, but also to see if there are new enhancements to take advantage of as well. Similar to the referenced issue, there are several things we can do across the entire rule set to improve

Tasks