Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

updating CSM rules doc with policy info #27385

Open
wants to merge 8 commits into
base: master
Choose a base branch
from

Conversation

michaelcretzman
Copy link
Contributor

We now group CSM Agent rules into policies. This doc update covers this new feature.

We now group CSM Agent rules into policies. This doc update covers this new feature.
added new policy feature for CSM Threats Agent Configuration rules
@michaelcretzman michaelcretzman added the editorial review Waiting on a more in-depth review label Jan 30, 2025
@michaelcretzman michaelcretzman self-assigned this Jan 30, 2025
@michaelcretzman michaelcretzman requested a review from a team as a code owner January 30, 2025 21:54
@github-actions github-actions bot added the Architecture Everything related to the Doc backend label Jan 30, 2025
Copy link
Contributor

Preview links (active after the build_preview check completes)

Modified Files

@michaelcretzman
Copy link
Contributor Author

Ed review topic was created: https://datadoghq.atlassian.net/browse/DOCS-9980

Copy link

@clachner clachner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks great! just some nitpicks / questions

@janine-c janine-c self-assigned this Jan 31, 2025
Copy link
Contributor Author

@michaelcretzman michaelcretzman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

incorp Eng review

incorp Eng review feedback
Copy link

@clachner clachner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Copy link
Contributor

@janine-c janine-c left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey Michael, looks great! I had some questions about the structure of the page, and then a small typo change. Let me know if there's anything you'd like to chat about, or if you'd like me to take another look, or any other way I can help 🙂

Comment on lines 20 to 24
In addition to the out of the box (OOTB) [default Agent and detection rules][7], you can write custom Agent and detection rules. Custom rules help to detect events Datadog is not detecting with its OOTB rules.

Agent rules are collected in policies. First, you create a policy, and then you add the custom rules you want applied by the policy.

When you create an Agent configuration policy it contains the default rules only. You can add custom rules to the policy to target specific infrastructure locations.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There seems to be a clear sequence here where you create policies, then add rules, but the descriptions of both of those things bounce back and forth between the two a bit. Can we make the descriptions line up with the sequence a bit better here (that is, explain what a policy is and that you have to make one first, then explain what a rule is and talk about how it relates to policies)?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the reason I did it this way was you can't explain that a policy is a collection of rules without first explaining what a rule is.

incorp edit review changes. still a few more to do but need to do them locally

Co-authored-by: Janine Chan <[email protected]>
Copy link
Contributor Author

@michaelcretzman michaelcretzman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

incorp edit review

Comment on lines 20 to 24
In addition to the out of the box (OOTB) [default Agent and detection rules][7], you can write custom Agent and detection rules. Custom rules help to detect events Datadog is not detecting with its OOTB rules.

Agent rules are collected in policies. First, you create a policy, and then you add the custom rules you want applied by the policy.

When you create an Agent configuration policy it contains the default rules only. You can add custom rules to the policy to target specific infrastructure locations.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the reason I did it this way was you can't explain that a policy is a collection of rules without first explaining what a rule is.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Architecture Everything related to the Doc backend editorial review Waiting on a more in-depth review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants