Skip to content

Clarify Risk Insights supported log sources and OCSF requirement - #39086

Merged
jenny-park-dd merged 1 commit into
masterfrom
jenny.park/risk-insights-supported-log-sources
Aug 11, 2026
Merged

Clarify Risk Insights supported log sources and OCSF requirement#39086
jenny-park-dd merged 1 commit into
masterfrom
jenny.park/risk-insights-supported-log-sources

Conversation

@jenny-park-dd

Copy link
Copy Markdown
Contributor

🚧 Draft / work in progress — not ready to merge. Sharing for feedback.

What

Rewrites the Risk Insights Prerequisites section to list all supported log sources, grouped by the entities each provides, and to state that an active OCSF pipeline is part of the requirement.

Why

The section previously listed four sources (GitHub, Azure, GCP, AWS) and did not mention OCSF at all. A reader could configure a supported source, have logs flowing, and still see no entities — with nothing on the page explaining why.

Link reference changes

  • Removed [1], [5], [6] (AWS/GCP/Azure config guides) — no longer referenced now that source names are unlinked
  • Added [8] for the out-of-the-box OCSF pipelines section
  • [3] remains defined-but-unused; pre-existing, left untouched

@jenny-park-dd jenny-park-dd added the WORK IN PROGRESS No review needed, it's a wip ;) label Aug 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@jenny-park-dd
jenny-park-dd force-pushed the jenny.park/risk-insights-supported-log-sources branch 2 times, most recently from fd2cc70 to 79efb4c Compare August 11, 2026 03:13
@jhgilbert jhgilbert added the astro-reorg-no-conflicts Needs manual conflict resolution after replatforming reorg label Aug 11, 2026
@jenny-park-dd
jenny-park-dd requested a review from finleye August 11, 2026 14:01
The Prerequisites section listed four supported log sources and did not
mention that Risk Insights requires an active OCSF pipeline, so a reader
could configure a supported source and still see no entities.

- List the supported log sources, grouped by the entities each provides
- State that an active OCSF pipeline is part of the requirement
- Add guidance for when a supported source produces no entities

Removes the AWS, Azure, and GCP config-guide link references, which are
no longer used now that the source names are unlinked.

Co-Authored-By: Claude <noreply@anthropic.com>
@jenny-park-dd
jenny-park-dd force-pushed the jenny.park/risk-insights-supported-log-sources branch from 79efb4c to 3c8afe2 Compare August 11, 2026 14:09
@jenny-park-dd
jenny-park-dd requested a review from finleye August 11, 2026 14:20
@jenny-park-dd
jenny-park-dd marked this pull request as ready for review August 11, 2026 14:21
@jenny-park-dd
jenny-park-dd requested a review from a team as a code owner August 11, 2026 14:21
@jenny-park-dd jenny-park-dd removed the WORK IN PROGRESS No review needed, it's a wip ;) label Aug 11, 2026
@evazorro evazorro changed the title [WIP] Clarify Risk Insights supported log sources and OCSF requirement Clarify Risk Insights supported log sources and OCSF requirement Aug 11, 2026

@evazorro evazorro left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, thank you!

@jenny-park-dd
jenny-park-dd merged commit 78ec89e into master Aug 11, 2026
34 of 35 checks passed
@jenny-park-dd
jenny-park-dd deleted the jenny.park/risk-insights-supported-log-sources branch August 11, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

astro-reorg-no-conflicts Needs manual conflict resolution after replatforming reorg

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants