docs: close issue retention

This commit is contained in:
Shirofune-Security
2026-09-22 18:20:17 +09:00
parent 76af0e92d8
commit fd9275b1ca
2 changed files with 5 additions and 0 deletions
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)
- Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435))
**Improvements:**
+3
View File
@@ -77,3 +77,6 @@ Before closing issue #382, use an isolated multi-host lab to compare source/coll
Primary references: [Microsoft WEF operational behavior and delivery formats](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/use-windows-event-forwarding-to-assist-in-intrusion-detection), [native source-initiated subscription validation](https://learn.microsoft.com/en-us/windows/win32/wec/setting-up-a-source-initiated-subscription), [Windows Time query tools](https://learn.microsoft.com/en-us/windows-server/networking/windows-time-service/windows-time-service-tools-and-settings), [Get-WinEvent ordering/query controls](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/get-winevent), [Security log clear 1102](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-1102), [Security log full 1104](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-1104).
Selected subscriptions also expose [typed local WEC runtime observations](wec-runtime.md) as `TypedRuntime`, alongside unchanged raw native evidence. Partial or unknown runtime reads remain explicit; Active and historical source inventory do not establish event delivery, backlog or retention compliance.
# Issue 382 coverage
The retention report now keeps local buffer age, bounded event-rate projections, archive declarations, time-source observations, subscription runtime queries, and rollover boundaries as separate evidence. A buffer size or sampled record age never counts as central retention, archival capacity, forwarding health, or loss-free coverage. Collector operators must provide an explicit archive declaration and subscription IDs; unobserved delivery, access, and cross-host clock agreement remain `Unknown`.