feat(soc-optimization-unified): add SOCFW Framework Health dashboard - #1174
Merged
Merged
Conversation
The framework-health half of the 15 Sep dashboard split. Lifecycle-outcome dashboards moved to the NIST IR packs in #1169-#1171; this is the other half and it ships in core. Command errors first, because the data found a live problem: on a reference tenant, 3,830 of 5,771 command executions over 30 days carry has_error, every one of them action_status = integration_unavailable. Nothing surfaced that. Seven widgets: - Command Error Rate (%) and Failed Commands, side by side - Minutes Credited to Failed Commands - the value-inflation number, to read against hours returned on the NIST IR dashboards - Failures by Universal Command - which framework verb is failing - Failure Reason - by action_status; does not assume integration_unavailable - Failing Commands, Detail - the drilldown: verb, product, vendor command, reason and affected case count per failing command - Command Failures by Day - a single bad day dominates a 30-day average, so the trend has to be readable beside the rate Structure copied from an existing shipped dashboard rather than authored from scratch: xql_<epoch> widget keys, row-<digits> row ids, default_dashboard_id left at the platform constant 1, is_public/is_predefined/creator_mail on every widget. Every query run against a reference tenant before it went in the file.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The framework-health half of the 15 Sep dashboard split. Lifecycle-outcome dashboards moved to the NIST IR packs in #1169-#1171; this is the other half and it ships in core.
Command errors first, because the data found a live problem nothing was surfacing.
What it shows
Measured on a reference tenant over 30 days:
has_erroraction_status = integration_unavailableNine widgets
soc-enrich-endpointappears twice against two different vendor commandssimulated, which is shadow mode working rather than a faultplaybook_tasks:socfw-post-to-datasetfailed 1,274 times, so the execution dataset is missing rows and every metric built on it understatesBuild notes
Structure copied from a shipped dashboard rather than authored from scratch. Two install rules learned the hard way, both via 101704:
| viewclause — every other type requires onelinechart type in the shipped vocabulary (single, column, pie, funnel, table only)default_dashboard_idleft absent, matching the Value Driver dashboards. Widget keys conform toxql_<13-digit epoch>, row ids torow-<digits>.Verification
Iterated through the dashboards REST API (
/public_api/v1/dashboards/{get,insert,delete}) rather than repeated pack installs, so no orphaned dashboards were created while building. Every query run against a reference tenant before it went in the file.check_contributionincluding the upload step, green.