From 9d2be764a36b06a52dfd4fe69e4e69f83ef2d807 Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Wed, 15 Jan 2025 16:03:42 +0100 Subject: [PATCH] improvements --- data_sources/{github.yml => github_enterprise_audit_logs.yml} | 2 +- ...ependabot.yml => github_enterprise_disable_dependabot.yml} | 4 ++-- macros/github_enterprise.yml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) rename data_sources/{github.yml => github_enterprise_audit_logs.yml} (97%) rename detections/cloud/{github_disable_dependabot.yml => github_enterprise_disable_dependabot.yml} (97%) diff --git a/data_sources/github.yml b/data_sources/github_enterprise_audit_logs.yml similarity index 97% rename from data_sources/github.yml rename to data_sources/github_enterprise_audit_logs.yml index 2d81c6cf0b..73532034df 100644 --- a/data_sources/github.yml +++ b/data_sources/github_enterprise_audit_logs.yml @@ -1,4 +1,4 @@ -name: GitHub +name: GitHub Enterprise Audit Logs id: 8a4d656f-8801-4a2c-ae10-553d2696a59f version: 1 date: '2025-01-15' diff --git a/detections/cloud/github_disable_dependabot.yml b/detections/cloud/github_enterprise_disable_dependabot.yml similarity index 97% rename from detections/cloud/github_disable_dependabot.yml rename to detections/cloud/github_enterprise_disable_dependabot.yml index b4299774c0..b7f4745a20 100644 --- a/detections/cloud/github_disable_dependabot.yml +++ b/detections/cloud/github_enterprise_disable_dependabot.yml @@ -1,4 +1,4 @@ -name: GitHub Disable Dependabot +name: GitHub Enterprise Disable Dependabot id: 787dd1c1-eb3a-4a31-8e8c-2ad24b214bc8 version: 1 date: '2025-01-14' @@ -19,7 +19,7 @@ search: '`github_enterprise` action=repository_vulnerability_alerts.disable | stats count min(_time) as firstTime max(_time) as lastTime by actor, actor_id, actor_ip, actor_is_bot, actor_location.country_code, business, business_id, org, org_id, repo, repo_id, user, user_agent, user_id, action | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `github_disable_dependabot_filter`' -how_to_implement: You must ingest GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk . +how_to_implement: You must ingest GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector. known_false_positives: unknown references: - https://www.googlecloudcommunity.com/gc/Community-Blog/Monitoring-for-Suspicious-GitHub-Activity-with-Google-Security/ba-p/763610 diff --git a/macros/github_enterprise.yml b/macros/github_enterprise.yml index 5028602761..b605cd7870 100644 --- a/macros/github_enterprise.yml +++ b/macros/github_enterprise.yml @@ -1,4 +1,4 @@ -definition: sourcetype=github:cloud:audit +definition: source=http:github sourcetype=httpevent description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment. name: github_enterprise \ No newline at end of file