Bias Analysis
Detected Bias Types
windows_first
powershell_heavy
windows_tools
missing_linux_example
Summary
The documentation demonstrates a Windows bias in several areas. Examples and instructions for deploying and managing parsers frequently reference Windows-centric tools and workflows, such as PowerShell scripts and the Azure portal, with no mention of Linux alternatives. The use of Windows event sources (e.g., 'Microsoft-Windows-Sysmon') is prioritized in examples, and deployment steps reference deleting functions via a PowerShell tool. There is a lack of explicit Linux or cross-platform guidance, and Linux-native tools or CLI workflows are not discussed, even though Sentinel and KQL can be used from Linux environments.
Recommendations
- Provide equivalent Linux/bash examples for deployment, such as using Azure CLI or REST API instead of PowerShell.
- Include instructions for managing ARM templates and functions from Linux/macOS environments.
- Balance examples between Windows and Linux event sources (e.g., show Syslog and Windows Event Log examples side-by-side).
- Reference cross-platform tools (e.g., Azure CLI, VS Code) before or alongside Windows-specific tools.
- Clarify that all steps can be performed from Linux environments and provide explicit commands or scripts.
- Add troubleshooting and testing guidance for Linux users, including how to export data and run KQL queries from Linux.
Create Pull Request