diff --git a/contentctl_test.yml b/contentctl_test.yml index be293d2b9a..534b4aa997 100644 --- a/contentctl_test.yml +++ b/contentctl_test.yml @@ -19,13 +19,15 @@ apps: splunkbase_path: null environment_path: ENVIRONMENT_PATH_NOT_SET force_local: false +# The Following TA does NOT exist on Splunkbase. It fixes a parsing issue that occurs when raw xmlwineventlog events +# are replayed together at a HEC endpoint. This issue does not exist when logs are sent by a Universal Forwarder - uid: 9999 - appid: Splunk_TA_windows - title: Splunk Add-on for Microsoft Windows + appid: Splunk_FIX_XMLWINEVENTLOG_HEC_PARSING + title: Splunk Fix XmlWinEventLog HEC Parsing description: null - release: 8.5.0_patched + release: 0.1 local_path: null - http_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850_PATCHED.tgz + http_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz splunkbase_path: null environment_path: ENVIRONMENT_PATH_NOT_SET force_local: false