Skip to content

[Feature Request] Update yaml schemas #3995

@user17286439

Description

@user17286439

Is your feature request related to a problem? Please describe.

  1. The detections .yml schema appears to be out of date. Fields that can be valid and used in detection content, specifically drilldown_searches and rba, are not reflected in the schema.
  2. data_sources and response_templates schemas are missing.

Describe the solution you'd like
Update the detection schema to include missing fields (drilldown_searches, rba, etc), add missing schemas (data_sources and response_templates) with appropriate types and constraints. This would bring the schema in sync with the actual capabilities supported by the detection .yaml format.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions