mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Merge pull request #485 from Shirofune-Security/feat/379-eventlog-closure
docs: close event-log retention gap (#379)
This commit is contained in:
5 files changed
+12
No files matched your search
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379)
|
||||
|
||||
- ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380)
|
||||
|
||||
- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381)
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379)
|
||||
|
||||
- Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380)
|
||||
|
||||
- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381)
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
# Event-log sizes and retention modes
|
||||
|
||||
### Issue 379 coverage
|
||||
|
||||
Event-log sizing and retention changes are explicit per-channel controls with typed before/after evidence, mode preservation, and guarded recovery. Buffer size does not establish a retention duration, archive capacity, forwarding health, or absence of event loss.
|
||||
|
||||
`audit-filesize` and ordinary `configure` now use the same
|
||||
`config/eventlog_profiles.json` definitions. `-Profile` continues to select
|
||||
**advanced audit policy only**. Use the separate `-LogProfile` option with
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379)
|
||||
|
||||
- ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380)
|
||||
|
||||
- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381)
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379)
|
||||
|
||||
- Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380)
|
||||
|
||||
- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381)
|
||||
|
||||
Reference in new issue
Block a user