Skip to main content

Automated Parser Update Notifications & Advanced Data Source Health Monitoring

  • July 15, 2026
  • 0 replies
  • 8 views

1. Executive Summary
Managing content updates and detecting subtle log ingestion drops currently requires high manual effort and leaves significant visibility gaps. We are requesting two distinct enhancement capabilities within the SNYPR console:

Automated Content Management Alerts: A proactive mechanism to notify engineers of available parser and content updates without requiring manual checks in the console daily.

Device-Level Log Status Visibility in Spotter: An improved ingestion health view that flags partial data drops (e.g., when a subset of devices within a multi-device data source stops reporting), preventing silent coverage gaps that are currently only caught during monthly EPS reporting.

2. Problem Statements & Impact
Issue A: Manual Content Management Tracking
Current Behavior: To keep up with content management and parser updates, analysts must manually log into the SNYPR console, navigate through the menus, and check for updates daily.

Operational Impact: This reactive approach introduces delays in deploying crucial parser fixes and updates. It creates unnecessary administrative overhead for the engineering team.

Issue B: Ingestion Blind Spots via Aggregated "Last Log Received"
Current Behavior: The Spotter page displays a high-level list of data sources showing the timestamp of the last log received. If a data source consists of 100 distinct reporting devices, the status appears green/current even if 99 of those devices have stopped sending logs, as long as a single device remains active.

Operational Impact: Silent failures and partial data drops go unnoticed for weeks. Because the total EPS does not drop to absolute zero, traditional "down" alerts are not triggered. We are currently discovering these gaps up to a month after the fact during monthly EPS report compilation, creating significant windows of unmonitored activity and compliance risks.

3. Proposed Features & Technical Requirements
Requirement 1: Proactive Parser & Content Update Alerts
Notification System: Implement an automated alert system (via Email, Webhook, or dedicated SNYPR System Alert) that triggers whenever a new update or patch is available for an onboarded parser or content pack.

Dashboard Indicator: Add a persistent, global visual badge or notification center icon in the main UI banner to highlight pending critical updates at a glance.

Requirement 2: Device-Level Health Granularity in Spotter
Per-Host Ingestion Tracking: Enhance the Spotter data source monitoring view to track the health of individual reporting hosts/devices within a given data source, rather than just evaluating the data source as a single aggregated unit.

Percentage/Threshold Ingestion Monitoring: Introduce a baseline comparison or threshold-based alerting mechanism. For example, if a data source typically sees 100 unique reporting hosts and that number drops below a configurable threshold (e.g., a 10% drop in active unique reporting hosts within a 24-hour window), generate a system health alert.

Visual Status Enhancements: Update the Spotter interface to show both the global "Last Log Received" time and an "Active/Total Devices" ratio (e.g., Active Devices: 74/100).

4. Business Value & Urgency
Implementing these features will significantly mature our platform operations by shifting our team from a reactive, manual review cycle to a proactive, automated workflow.

Security Posture: Ensures critical parser updates are applied immediately, reducing log parsing errors and ensuring threat detection rules function accurately.

Incident Prevention: Eliminates blind spots caused by silent log source failures, ensuring our security monitoring coverage remains continuous and reliable without waiting for monthly manual reviews.