From 5ea6155d96d7d9528dd51b04cb27a52c08a7a028 Mon Sep 17 00:00:00 2001 From: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com> Date: Fri, 4 Jul 2025 07:00:30 +0000 Subject: [PATCH] Updated TAs --- contentctl.yml | 4 ++-- data_sources/github_enterprise_audit_logs.yml | 19 ++++++++++++++----- .../github_organizations_audit_logs.yml | 18 +++++++++++++----- 3 files changed, 29 insertions(+), 12 deletions(-) diff --git a/contentctl.yml b/contentctl.yml index b078b28859..5cea12db12 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -215,9 +215,9 @@ apps: - uid: 6254 title: Splunk Add-on for Github appid: Splunk_TA_github - version: 3.1.0 + version: 3.2.0 description: description of app - hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_310.tgz + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_320.tgz - uid: 3471 title: Splunk Add-on for AppDynamics appid: Splunk_TA_AppDynamics diff --git a/data_sources/github_enterprise_audit_logs.yml b/data_sources/github_enterprise_audit_logs.yml index f2f2da3187..10b9654094 100644 --- a/data_sources/github_enterprise_audit_logs.yml +++ b/data_sources/github_enterprise_audit_logs.yml @@ -3,17 +3,19 @@ id: 8a4d656f-8801-4a2c-ae10-553d2696a59f version: 1 date: '2025-01-15' author: Patrick Bareiss, Splunk -description: Data source object for GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector. +description: Data source object for GitHub Enterprise logs using Audit log streaming + as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk + using a Splunk HTTP Event Collector. source: http:github sourcetype: httpevent -supported_TA: +supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.1.0 + version: 3.2.0 fields: - _document_id - action -- actor +- actor - actor_id - actor_is_bot - business @@ -29,4 +31,11 @@ fields: - user - user_agent - user_id -example_log: '{ @timestamp: 1736850926658 _document_id: fHPRFHOMZNXLxTZrk1w2IQ action: repository_vulnerability_alerts.disable actor: P4T12ICK actor_id: 8362376 actor_ip: 84.128.62.13 actor_is_bot: false actor_location: { [+] } business: pb business_id: 273781 created_at: 1736850926658 operation_type: modify org: pbtest2 org_id: 194489467 public_repo: false repo: pbtest2/pbtest5 repo_id: 916529548 request_access_security_header: null user: P4T12ICK user_agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 user_id: 8362376 }' \ No newline at end of file +example_log: '{ @timestamp: 1736850926658 _document_id: fHPRFHOMZNXLxTZrk1w2IQ action: + repository_vulnerability_alerts.disable actor: P4T12ICK actor_id: 8362376 actor_ip: + 84.128.62.13 actor_is_bot: false actor_location: { [+] } business: pb business_id: + 273781 created_at: 1736850926658 operation_type: modify org: pbtest2 org_id: 194489467 + public_repo: false repo: pbtest2/pbtest5 repo_id: 916529548 request_access_security_header: + null user: P4T12ICK user_agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) + AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 user_id: 8362376 + }' diff --git a/data_sources/github_organizations_audit_logs.yml b/data_sources/github_organizations_audit_logs.yml index faa3002557..6d9dfc3b2d 100644 --- a/data_sources/github_organizations_audit_logs.yml +++ b/data_sources/github_organizations_audit_logs.yml @@ -3,17 +3,18 @@ id: ce520b1c-79fe-48ef-a0f9-71fbbd4837b0 version: 1 date: '2025-01-15' author: Patrick Bareiss, Splunk -description: Data source object for GitHub Organizations logs using the Splunk Add-on for Github using a Personal Access Token. +description: Data source object for GitHub Organizations logs using the Splunk Add-on + for Github using a Personal Access Token. source: github sourcetype: github:cloud:audit -supported_TA: +supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.1.0 + version: 3.2.0 fields: - _document_id - action -- actor +- actor - actor_id - actor_is_bot - business @@ -29,4 +30,11 @@ fields: - user - user_agent - user_id -example_log: '{ @timestamp: 1736850926658 _document_id: fHPRFHOMZNXLxTZrk1w2IQ action: repository_vulnerability_alerts.disable actor: P4T12ICK actor_id: 8362376 actor_ip: 84.128.62.13 actor_is_bot: false actor_location: { [+] } business: pb business_id: 273781 created_at: 1736850926658 operation_type: modify org: pbtest2 org_id: 194489467 public_repo: false repo: pbtest2/pbtest5 repo_id: 916529548 request_access_security_header: null user: P4T12ICK user_agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 user_id: 8362376 }' \ No newline at end of file +example_log: '{ @timestamp: 1736850926658 _document_id: fHPRFHOMZNXLxTZrk1w2IQ action: + repository_vulnerability_alerts.disable actor: P4T12ICK actor_id: 8362376 actor_ip: + 84.128.62.13 actor_is_bot: false actor_location: { [+] } business: pb business_id: + 273781 created_at: 1736850926658 operation_type: modify org: pbtest2 org_id: 194489467 + public_repo: false repo: pbtest2/pbtest5 repo_id: 916529548 request_access_security_header: + null user: P4T12ICK user_agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) + AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 user_id: 8362376 + }'