mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
remove risk_score field from all
detections. this is a calculated field and should not be included
This commit is contained in:
@@ -42,7 +42,6 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
risk_score: 9
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
Reference in New Issue
Block a user