Skip to content

Conversation

@ben-githubs
Copy link
Contributor

Background

We noticed some GCP rules are especially noisy and decided to investigate. These two are low-severity issues which don't need to be alerted on as much as they are.

Changes

  • GCP.Access.Attempts.Violating.VPC.Service.Controls
    • severity downgraded to LOW
    • threshold set to 1000
    • runbook added and description changed slightly
    • dedup period changed from 1 hour to 1 day
  • GCP.K8s.Pod.Using.Host.PID.Namespace
    • downgraded to signal

Testing

  • Unit tests all still pass
  • Simulations on customer alert metrics indicates the number of alerts for GCP.Access.Attempts.Violating.VPC.Service.Controls would be decreased from 666 alerts 👿 to 20, over a 6-week period.

@ben-githubs ben-githubs requested a review from a team as a code owner July 31, 2025 17:00
@ben-githubs
Copy link
Contributor Author

Idk why the test failed.... it failed for a rule that I didn't even edit

@arielkr256 arielkr256 added the tuning detection tuning label Aug 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tuning detection tuning

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants