A parse failure looks like silence
When a parser breaks, your rules still run and still return nothing. Zero matches and zero activity produce the same dashboard.
A rule reads fields. Fields come from a parser. When the parser breaks, the rule still runs, still returns nothing, and still reports healthy.
That is the whole problem. A parse failure and a quiet week produce identical output: zero matches.
Parsers break for boring reasons. A vendor adds a column to the middle of a CSV. An agent upgrade switches from key-value pairs to JSON. A multi-line stack trace arrives and every line becomes its own event. None of these raise an error your detection can see, because the damage happened upstream of the rule.
The evidence is in the data rather than in the alerts. Events still arrive, so a volume check passes and your source-silence monitoring stays quiet. But the fields your rules depend on are null, or everything has landed in a catch-all message blob, or the event type now reads as unknown.
So monitor the parse, not just the ingest. Count events where the fields your detections actually read are empty. Track the ratio of unparsed to parsed events per source, and alert when that ratio moves, because it moves on the day of an upgrade and not before.
Pick your three most important rules. List the fields each one reads. Then go and check how many events from those sources arrived today with those fields empty.
CHECK YOURSELF
A detection that normally fires a few times a week has fired zero times for nine days. Event volume from the source looks normal. What do you check first?
SHOW THE ANSWER
Whether the fields the rule reads are still being populated
Why. Normal event volume rules out an ingest failure, which is the usual first guess, and says nothing at all about parsing. A parser change fills the pipeline with events that arrive on time, count correctly, and match nothing, because the field your rule reads is now empty or renamed. Confirm the fields are populated before you rewrite logic or conclude that nothing happened.