Skip to content

docs(splunk): fix disposition join key to correlation_id::rule_id - #102

Merged
blitzcrieg1 merged 1 commit into
masterfrom
fix/fleet-siem-disposition-join-key
Aug 23, 2026
Merged

docs(splunk): fix disposition join key to correlation_id::rule_id#102
blitzcrieg1 merged 1 commit into
masterfrom
fix/fleet-siem-disposition-join-key

Conversation

@blitzcrieg1

Copy link
Copy Markdown
Owner

Summary

  • Fix untriaged-detection join in fleet-via-siem.md from single colon to double colon

Why

disposition.py uses correlation_id::rule_id as detection_key. A single-colon join silently misses every closure, so SOC searches never drop triaged findings.

Matches enterprise TA saved search Untriaged critical or high in agentmetry-enterprise PR #9.

Test plan

  • Doc-only change; join key matches docs/integrations/sigma/agentmetry_critical_detection_untriaged.yml comments

Single-colon joins silently miss every closure. Matches disposition.py
detection_key and the enterprise TA saved searches.
@blitzcrieg1
blitzcrieg1 merged commit ebff183 into master Aug 23, 2026
9 checks passed
@blitzcrieg1
blitzcrieg1 deleted the fix/fleet-siem-disposition-join-key branch August 23, 2026 10:27
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 23, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant