Bias Analysis
Detected Bias Types
windows_first
windows_tools
missing_linux_example
Summary
The documentation page demonstrates a notable Windows bias. Several deprecated connectors and data collection instructions focus on Windows agents, Windows machines, and Windows-specific event types (e.g., SecurityEvent, IIS logs). Windows examples and prerequisites are presented before or instead of Linux equivalents. While there is a section for Syslog (Linux), most other connectors lack explicit Linux instructions or parity, and Windows tooling (agents, event types) is referenced more frequently and prominently.
Recommendations
- For each connector, explicitly document Linux/macOS support, including prerequisites and installation steps for non-Windows platforms.
- Where Windows agents or event types are referenced, provide equivalent Linux/macOS agent instructions (e.g., AMA on Linux, syslog, auditd, etc.) and event types.
- Present Linux/macOS examples and tools alongside or before Windows examples to ensure parity.
- Clarify which connectors are Windows-only and which support cross-platform ingestion, and provide migration guidance for Linux users where relevant.
- Add links to Linux/macOS agent installation guides and troubleshooting resources.
Create Pull Request