mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
remove risk_score field from all
detections. this is a calculated field and should not be included
This commit is contained in:
@@ -41,7 +41,6 @@ tags:
|
||||
- eventName
|
||||
- userAgent
|
||||
- errorCode
|
||||
risk_score: 63
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
Reference in New Issue
Block a user