Expand risk message validation to ensure appropriate field values are present
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
Research direction
Locate the existing risk message validation entry point and trace how raw events and field tokens are handled. Determine the expected field values from the raw event and verify that each appears in the risk message, while preserving the existing unreplaced-token check. Done means validation rejects messages missing expected values and accepts complete messages.
Written by the indexing model from the issue text.
Description
- During risk message validation, we ensure that none of the field tokens remain unreplaced in the risk event message
- We could take this an additional step by determining the expected field values from the raw event, and ensuring they all DO appear in the risk message as well
- Dominant language
- Python
- Stars
- 139
- Forks
- 51
- Avg merge
- 1h 16m
- Merged PRs (30d)
- 3
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from splunk/contentctl
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 45/100
splunk/contentctl#468 · 1 comment ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 38/100
splunk/contentctl#461 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 48/100
splunk/contentctl#452 ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
splunk/contentctl#464 · 3 comments ·
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
splunk/contentctl#451 ·
All issues in splunk/contentctl
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
raullenchai/Rapid-MLX#4042 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
LearningCircuit/local-deep-research#7067 ·
Maintainers usually reply within 1 day
-
#bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
apache/superset#44923 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
lawndoc/stack-back#123 ·