Published 16 days ago
Published 16 days ago
r_0xc137
Updated 16 days ago
0
Hi,
Today: rules can only be built and maintained in the visual builder.
Problem: nested AND/OR/NOT logic is slow to assemble and hard to read back; changes can't be reviewed as a diff; rules can't live in Git alongside the rest of our infrastructure config; promoting configuration between environments means manual re-creation and drift.
Request:
Benefit: ccomplex rules creation and maintenance, code review and CI/CD for detection rules, reproducible configuration, fewer manual-entry errors, audit-ready change evidence, fast promotion between environments
Windsley
Updated 16 days ago
0
Thank you for sharing this feedback. We recognize the challenges involved in managing and configuring complex rules, particularly the scenarios you outlined.
MCP is already on our roadmap and is planned for release soon. Once available, it may provide a useful way to explore some of these rule-management use cases. We welcome you to try it and share your feedback, which will help us better understand your requirements.
r_0xc137
Updated 14 days ago
0
Hi,
Do you plan to add a rule syntax field instead of a rule builder? Or only MCP server?
Windsley
Updated 14 days ago
Our current direction is to make this capability available through MCP.