Skip to content

Development to 0.6.0 - #324

Merged
ipmach merged 41 commits into
mainfrom
development
Sep 30, 2026
Merged

ipmach merged 41 commits into
mainfrom
development

Conversation

@ipmach

@ipmach ipmach commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Task

Description

How Has This Been Tested?

Checklist

  • This Pull-Request goes to the development branch.
  • I have successfully run prek locally.
  • I have added tests to cover my changes.
  • I have linked the issue-id to the task-description.
  • I have performed a self-review of my own code.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Leokaufi and others added 30 commits September 15, 2026 13:20
… again in the docu; fix some grammatic mistakes
…he automate function for the configuration arguments for the documentation
…ication

Window selection was the one auto-configuration still decided by the
library default rule. SequenceAutoConfigParams carried no classification
block, and the detector built its configure-phase trackers with
VariablesLogic's default, so a run that graded every variable detector by
a chosen rule graded candidate windows by another one. The configure
phase also ingested without timestamps, so an enabled time-axis method
silently fell back to the index axis.

Split StabilityAutoConfigParams out of VariableAutoConfigParams to hold
classification, timestamp_variable and timestamp_format -- the sequence
detector needs those three and none of the variable-only flags. Inherit
it in SequenceAutoConfigParams, hand the block to VariablesLogic, and
pass the per-record timestamp to ingest_event.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
… the automate function for the configuration arguments for the documentation
…ield function and the automate function for the configuration arguments for the documentation
… the automate function for the configuration arguments for the documentation
The configure phase ran whenever data_use_configure was set, whatever
auto_config said. With auto_config=False a NewValueDetector's explicit
events block was overwritten, EventSequenceDetector picked a window
length, and DrainParser ran its hyperparameter search -- contradicting
the documented "steps 1 and 2 are skipped entirely".

Gate both calls in CoreComponent.process. The configure window still
consumes its records and, with use_config_data_as_training, still hands
them to training, so a config rerun with auto_config=False trains on
the same data as the configuring run.

The bigram auto-config test built its detector with auto_config=False
and only passed because the configure phase ignored the flag; it now
enables auto_config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
save() swallowed write errors and reset events_since_save before writing,
so a failed save looked successful. It now raises PersistencySaveError and
clears only the events captured in the saved snapshot, after the write
succeeds. Timer and event-count saves log the failure at ERROR instead of
raising, and the count trigger backs off after a failure.

Fixes #319
Removed docstring explaining the configuration inputs for stability verdicts.
…error

Raise PersistencySaveError when PersistencySaver.save() fails
- docs tables now show all arguments per component, grouped by YAML block
  (top level / params / auto_config_params) in collapsible sections, with a
  Scope column marking detector-specific vs shared fields and changed defaults
- get_docs() expands auto_config_params (nested fields as dotted names) and
  documents persist; field descriptions added where missing
- generated YAML examples include auto_config_params and are checked to load
  back; event_sequence.md is now generated too (its hand-written YAML was wrong)
- add mkdocs-material to dev dependencies, enable admonition/details
- add Leonhard Kaufmann to authors, fix dead tutorial link
Every parser and detector page now shows a hand-written configuration
file that sets only what its use case needs, loaded by the page's Python
example so the snippet tests keep it valid. The full-defaults YAML block
generated by update.py is removed; all parameters remain in the generated
argument tables, with auto_config_params collapsed by default.

- detector examples train on realistic sshd logs and print a real alert
  (combo now uses two variables)
- pages reordered: At a glance, Description, Example, Configuration file,
  Configuration arguments
- fix the broken YAML in detectors.md and warn that data_use_training /
  data_use_configure must be set
- move auto-config implementation internals to development.md
- fix the duplicated Drain example and drop the redundant LogBatcher one
- number detectors 00-12 in the sidebar, ordered from simplest to most
  complex, and note the ordering in the detectors overview
- align page titles and prose (Rule Detector, New Value Combo Detector,
  DeepLog, LogBERT, JSON/Drain Parser, Template Matcher)
- rename deeplog/logbert example files to match their page names
- export all detectors from detectmatelibrary.detectors, loading the
  JAX-based DeepLog and LogBERT lazily
- rename ECVC method_type to ecvc_detector; the old
  ecvc_detector_detector still loads with a DeprecationWarning
…fication-config

Let EventSequenceDetector auto-configure under the configured classif…
Comment thread src/detectmatelibrary/detectors/__init__.py Dismissed
Comment thread src/detectmatelibrary/detectors/__init__.py Dismissed
Comment thread src/detectmatelibrary/detectors/__init__.py Dismissed
Comment thread src/detectmatelibrary/detectors/__init__.py Dismissed
Comment thread tests/test_persistency/test_persistency_saver.py Dismissed
Comment thread tests/test_persistency/test_persistency_saver.py Dismissed
Comment thread tests/test_persistency/test_persistency_saver.py Dismissed
Comment thread tests/test_persistency/test_persistency_saver.py Dismissed
Comment thread tests/test_persistency/test_persistency_saver.py Dismissed
@ipmach
ipmach merged commit 62c350a into main Sep 30, 2026
7 checks passed
@ipmach
ipmach deleted the development branch September 30, 2026 07:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants