SIEM Readiness: Visibility Health & Data Coverage
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**SIEM Readiness: Visibility Health & Data Coverage**
**Value proposition**
Elastic Security users ingest logs, enable rules, and deploy agents — but today there is no single place to answer: "Is my SIEM actually ready to detect threats?"
SOC teams maintain spreadsheets, build custom dashboards, and manually reconcile data sources against detection rules — only to discover gaps during audits or live incidents.
SIEM Readiness introduces a centralized, actionable health view inside Elastic Security that continuously evaluates whether you have the right data, in the right shape, with sufficient reliability and retention to support your active detections.
**Expected outcome**
A new SIEM Readiness page in Elastic Security that provides at-a-glance health across four dimensions:
**Coverage** — Are the data sources your detection rules depend on actually present? Which log categories (Endpoint, Identity, Network, Cloud, Application/SaaS) are covered vs. missing?
**Quality** — Are your logs ECS-compatible? Surface data sources with field mapping issues that silently break rules, dashboards, and correlations.
**Continuity** — Are your ingest pipelines healthy? Detect pipeline failures before they create blind spots.
**Retention** — Do your lifecycle policies meet industry benchmarks (FedRAMP, SOC 2, ISO 27001)? Flag categories falling short of recommended retention windows.
Every signal is tied to a guided action: view affected integrations, investigate in Discover, adjust policies, or generate a prefilled case to assign remediation to the right team.
**Optional: Key user stories / use cases**
- As a SOC Manager, I want a single readiness view that shows whether my SIEM has the right data for my detections, so I can report operational posture to leadership without maintaining spreadsheets.
- As a Detection Engineer, I want to see which enabled rules are missing required data sources (mapped by MITRE ATT&CK tactic), so I can prioritize onboarding the data that matters most.
- As a Platform Engineer, I want to know which ingest pipelines are failing and which data streams have ECS incompatibilities, so I can fix issues before they impact detections.
- As a Compliance Manager, I want to verify that log retention meets regulatory benchmarks across all categories, so I can prepare for audits without manual data collection.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.