What problem does it solve?
Security operators deploying runtime threat detection on NVIDIA BlueField DPUs often misconfigure the DOCA Argus container, leaving SIEM channels silently empty, flooding them with false positives, or creating undocumented blind spots. This Skill guides agents through correct Argus deployment, configuration, calibration, and debugging so findings reliably reach the security operations team.
Core Features & Use Cases
- Four-Axis Configuration Guidance: Walks operators through committing to detection policy, forwarding destination, sampling sensitivity, and host coverage before starting the Argus container.
- End-to-End Pipeline Validation: Prescribes smoke tests proving findings traverse Argus container, forwarder, SIEM ingest, and ops review before production alerting is enabled.
- Layered Debug Taxonomy: Diagnoses failures across five layers (container runtime, detection policy, forwarding, sampling/performance, host coverage) with explicit clearing criteria per layer.
- Use Case: An operator sees a green Argus container but zero findings in Splunk after 24 hours; the Skill routes diagnosis to the detection-policy or forwarding layer instead of blindly rewriting configuration.
Quick Start
Ask your agent to help deploy the DOCA Argus container on a BlueField-3 and forward its security findings to your Splunk instance.