Clarify delayed-rule catch-up behavior before gaps are recorded in Security rule monitoring docs - #7830
Clarify delayed-rule catch-up behavior before gaps are recorded in Security rule monitoring docs#7830bmorelli25 with Copilot wants to merge 4 commits into
Conversation
Co-authored-by: bmorelli25 <5618806+bmorelli25@users.noreply.github.com>
Co-authored-by: bmorelli25 <5618806+bmorelli25@users.noreply.github.com>
|
@nastasha-solomon this one felt well scoped enough for me to throw copilot at. If we're too far off, close this and we can reassess. |
Elastic Docs AI PR menuCheck the box to run an AI review for this pull request.
Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team. |
🔍 Preview links for changed docs |
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
@bmorelli25 I'm not the biggest fan of the updates that copilot made. I read the doc issue as: users want to know if rules running on a late schedule (e.g., they were queued or took a long time to execute) extend their search window to cover the "missed" time window. The updates don't explicitly confirm this, and instead jump to explaining how the rule's catch-up window works and what the UI displays. I'd like to take a whack at this PR when I'm back from PTO and/or consider how to better direct copilot with these types of updates. |
|
Works for me! Thanks! |
The docs for rule monitoring and gap filling did not explain why a rule can show scheduling delay while gap duration remains empty/zero. This update documents the catch-up window behavior so users can distinguish expected delay recovery from true coverage gaps.
What was missing
monitor-rule-executions.mdupdates (Scheduling and gaps)0Gap durationinterval-sized windowsfill-rule-gaps.mdupdates (Gap information)0