Conversation
"Virtual Machine Escape Detection", "ESXi Syslog Forwarding Disruption Detection" and "ESXi Firewall Rule Modification Detection" grouped by adversary.hostname, which ESXi alerts never carry. Grouping keys that do not resolve are skipped, so the syslog and firewall rules opened a new top-level alert for every matching record and the VM escape rule, left with lastEvent.log.process, stored a child alert for every record. Each rule now de-duplicates for seven days: per ESXi host (dataSource) and, for the VM escape rule, per process. Their conditions are unchanged. vmware_esxi_alert_volume_test.go pins the keys and checks that they resolve on parsed ESXi records. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Three ESXi rules break the limit of 10 alerts per hour on the one v11 deployment that sends ESXi logs (three hosts). Between 2026-09-28 00:00 and 2026-09-29 18:00 UTC:
All three group by
adversary.hostname, which ESXi alerts never carry (the ESXi filter writes noorigin.hostname). Grouping keys that do not resolve are skipped, so the syslog and firewall rules opened a new top-level alert for every matching record, and the VM escape rule, left withlastEvent.log.process, stored a child alert for every record under one parent per process name.Noise is reduced here only by de-duplication. The conditions are unchanged, and nothing is excluded by name.
What changes
groupBylastEvent.log.process, adversary.hostnamededuplicateBydataSource, lastEvent.log.processgroupByadversary.hostnamededuplicateBydataSourcegroupByadversary.hostnamededuplicateBydataSourcedataSourceis the ESXi host. One alert is raised per host (and process, for the VM escape rule); repeats are dropped for seven days.Expected volume
Replaying 30 days of real records from the deployment's three ESXi hosts with the conditions as they are and seven-day de-duplication:
ESXi writes some of these records two to four at a time in the same second, and the engine stores alerts that arrive together in parallel, so each alert can come with up to three copies (at most 4 in any hour or day); that engine limit is separate from this change.
What the conditions matched is routine: guest file operations from vCenter's agent that returned FileNotFound or InvalidArgument (VM escape), the remote syslog host becoming unreachable (syslog disruption), and the configuration store processing its
nfs_firewall_rulesetsplug-in file (firewall modification). Narrowing those conditions is left for a separate review.Tests
plugins/alerts/vmware_esxi_alert_volume_test.go(new) evaluates parsed ESXi records (process and message) with the pinned go-sdk v1.1.36 CEL. It pins the de-duplication keys, checks that they resolve, and checks one record each rule must match and one it must not.go test ./...inplugins/alertspasses on this branch, which is based on currentv11(89cd26c4).8a3ade7, go-sdk v1.1.36, the production events and alerts plugins, OpenSearch 2.19.1, this branch's ESXi filter from currentv11) with fabricated ESXi syslog lines in two runs: one matching line per rule on one host plus two lines that must not match, then the same three lines again on that host and on a second host. Both runs processed all of their events, and the real parser filleddataSourceandlog.processon every line.adversary.hostnameresolved on none of them), and the VM escape rule stored one parent and two children, grouping both hosts under the process name.🤖 Generated with Claude Code