Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions packages/m365_defender/_dev/benchmark/rally/alert-benchmark.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
description: Benchmark 100000 m365_defender.alert events ingested
data_stream:
name: alert
corpora:
generator:
total_events: 100000
template:
type: gotext
path: ./alert-benchmark/template.ndjson
config:
path: ./alert-benchmark/config.yml
fields:
path: ./alert-benchmark/fields.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,128 @@
- name: id
cardinality: 100000
- name: providerAlertId
cardinality: 100000
- name: incidentId
cardinality: 100000
- name: status
cardinality: 100000
- name: severity
cardinality: 100000
- name: classification
cardinality: 100000
- name: determination
cardinality: 100000
- name: serviceSource
cardinality: 100000
- name: detectionSource
cardinality: 100000
- name: productName
cardinality: 100000
- name: detectorId
cardinality: 100000
- name: tenantId
cardinality: 100000
- name: title
cardinality: 100000
- name: description
cardinality: 100000
- name: recommendedActions
cardinality: 100000
- name: category
cardinality: 100000
- name: assignedTo
cardinality: 100000
- name: alertWebUrl
cardinality: 100000
- name: incidentWebUrl
cardinality: 100000
- name: actorDisplayName
cardinality: 100000
- name: threatDisplayName
cardinality: 100000
- name: threatFamilyName
cardinality: 100000
- name: mitreTechniques
cardinality: 100000
- name: createdDateTime
period: -24h
- name: lastUpdateDateTime
period: -24h
- name: resolvedDateTime
period: -24h
- name: firstActivityDateTime
period: -24h
- name: lastActivityDateTime
period: -24h
- name: alertPolicyId
cardinality: 100000
- name: additionalData
cardinality: 100000
- name: comments
cardinality: 100000
- name: evidence.internetMessageId
cardinality: 100000
- name: evidence.networkMessageId
cardinality: 100000
- name: evidence.senderIp
cardinality: 100000
- name: [email protected]
cardinality: 100000
- name: evidence.createdDateTime
period: -24h
- name: evidence.verdict
cardinality: 100000
- name: evidence.remediationStatus
cardinality: 100000
- name: evidence.remediationStatusDetails
cardinality: 100000
- name: evidence.roles
cardinality: 100000
- name: evidence.detailedRoles
cardinality: 100000
- name: evidence.tags
cardinality: 100000
- name: evidence.firstSeenDateTime
period: -24h
- name: evidence.mdeDeviceId
cardinality: 100000
- name: evidence.azureAdDeviceId
cardinality: 100000
- name: evidence.deviceDnsName
cardinality: 100000
- name: evidence.osPlatform
cardinality: 100000
- name: evidence.osBuild
cardinality: 100000
range:
min: 10
max: 10000
- name: evidence.version
cardinality: 100000
- name: evidence.healthStatus
cardinality: 100000
- name: evidence.riskScore
cardinality: 100000
- name: evidence.rbacGroupId
cardinality: 100000
range:
min: 10
max: 10000
- name: evidence.rbacGroupName
cardinality: 100000
- name: evidence.onboardingStatus
cardinality: 100000
- name: evidence.defenderAvStatus
cardinality: 100000
- name: evidence.ipInterfaces
cardinality: 100000
- name: evidence.vmMetadata
cardinality: 100000
- name: evidence.loggedOnUsers.accountName
cardinality: 100000
- name: evidence.loggedOnUsers.domainName
cardinality: 100000
- name: '@odata.context'
cardinality: 100000
- name: value
cardinality: 100000
Original file line number Diff line number Diff line change
@@ -0,0 +1,128 @@
- name: id
type: keyword
- name: providerAlertId
type: keyword
- name: incidentId
type: keyword
- name: status
type: keyword
- name: severity
type: keyword
- name: classification
type: keyword
- name: determination
type: keyword
- name: serviceSource
type: keyword
- name: detectionSource
type: keyword
- name: productName
type: keyword
- name: detectorId
type: keyword
- name: tenantId
type: keyword
- name: title
type: keyword
- name: description
type: keyword
- name: recommendedActions
type: keyword
- name: category
type: keyword
- name: assignedTo
type: keyword
- name: alertWebUrl
type: keyword
- name: incidentWebUrl
type: keyword
- name: actorDisplayName
type: keyword
- name: threatDisplayName
type: keyword
- name: threatFamilyName
type: keyword
- name: mitreTechniques
type: keyword
- name: createdDateTime
type: date
- name: lastUpdateDateTime
type: date
- name: resolvedDateTime
type: date
- name: firstActivityDateTime
type: date
- name: lastActivityDateTime
type: date
- name: alertPolicyId
type: keyword
- name: additionalData
type: keyword
- name: comments
type: keyword
- name: evidence
type: group
fields:
- name: internetMessageId
type: keyword
- name: networkMessageId
type: keyword
- name: senderIp
type: keyword
- name: '@odata.type'
type: keyword
- name: createdDateTime
type: date
- name: verdict
type: keyword
- name: remediationStatus
type: keyword
- name: remediationStatusDetails
type: keyword
- name: roles
type: keyword
- name: detailedRoles
type: keyword
- name: tags
type: keyword
- name: firstSeenDateTime
type: date
- name: mdeDeviceId
type: keyword
- name: azureAdDeviceId
type: keyword
- name: deviceDnsName
type: keyword
- name: osPlatform
type: keyword
- name: osBuild
type: long
- name: version
type: keyword
- name: healthStatus
type: keyword
- name: riskScore
type: keyword
- name: rbacGroupId
type: long
- name: rbacGroupName
type: keyword
- name: onboardingStatus
type: keyword
- name: defenderAvStatus
type: keyword
- name: ipInterfaces
type: keyword
- name: vmMetadata
type: keyword
- name: loggedOnUsers
type: group
fields:
- name: accountName
type: keyword
- name: domainName
type: keyword
- name: '@odata.context'
type: keyword
- name: value
type: keyword
Loading