elastic / elastic/roadmap

SIEM Readiness: Visibility Health & Data Coverage

Open
#226 0 comments 0 reactions 1 assignee Claimed by @smriti0321 View on GitHub
product-area:security v9.4.0
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**SIEM Readiness: Visibility Health & Data Coverage**

**Value proposition**

Elastic Security users ingest logs, enable rules, and deploy agents — but today there is no single place to answer: "Is my SIEM actually ready to detect threats?"

SOC teams maintain spreadsheets, build custom dashboards, and manually reconcile data sources against detection rules — only to discover gaps during audits or live incidents.

SIEM Readiness introduces a centralized, actionable health view inside Elastic Security that continuously evaluates whether you have the right data, in the right shape, with sufficient reliability and retention to support your active detections.

**Expected outcome**

A new SIEM Readiness page in Elastic Security that provides at-a-glance health across four dimensions:

**Coverage** — Are the data sources your detection rules depend on actually present? Which log categories (Endpoint, Identity, Network, Cloud, Application/SaaS) are covered vs. missing?
**Quality** — Are your logs ECS-compatible? Surface data sources with field mapping issues that silently break rules, dashboards, and correlations.
**Continuity** — Are your ingest pipelines healthy? Detect pipeline failures before they create blind spots.
**Retention** — Do your lifecycle policies meet industry benchmarks (FedRAMP, SOC 2, ISO 27001)? Flag categories falling short of recommended retention windows.
Every signal is tied to a guided action: view affected integrations, investigate in Discover, adjust policies, or generate a prefilled case to assign remediation to the right team.

**Optional: Key user stories / use cases**

- As a SOC Manager, I want a single readiness view that shows whether my SIEM has the right data for my detections, so I can report operational posture to leadership without maintaining spreadsheets.

- As a Detection Engineer, I want to see which enabled rules are missing required data sources (mapped by MITRE ATT&CK tactic), so I can prioritize onboarding the data that matters most.

- As a Platform Engineer, I want to know which ingest pipelines are failing and which data streams have ECS incompatibilities, so I can fix issues before they impact detections.

- As a Compliance Manager, I want to verify that log retention meets regulatory benchmarks across all categories, so I can prepare for audits without manual data collection.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.