So the Elastic Security team pushes out a detection pack for the Log4j CVE. Great. But is it just more alert noise?
* Their announcement touts "out-of-the-box" rules. How many are just repackaged generic rules we already tuned out?
* Did they document the false positive rate? Of course not.
* What's the actual coverage? Does it catch the obfuscated JNDI strings or just the obvious ones?
I'm more interested in the hidden costs:
* Does this pack assume a perfect, normalized log source most of us don't have?
* How much extra ingest will these rules chew through if you enable them all?
* Will support actually help you tune them, or just point you at the documentation?
Seen it in action yet? Was it useful or just a checkbox feature?
Read the contract