← 문제 라이브러리
Security Advanced SECURITY-1438 · 13 min

An Elastic SIEM rule goes quiet (siem-correlation-followed-legacy-field-after-semantic-drift)

Events still arrive, yet the rule watches a field whose meaning changed during normalization and no longer represents the admin action it expects.

Incident ResponsePro
시나리오

Ingest remains healthy and one critical admin …

구독하면 이어서 볼 수 있어요

이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.

구독 안내 보기