From ccc1946e6441ea65b2e9f465926b27f31721febe Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 30 Jun 2025 11:58:48 -0700 Subject: [PATCH] Update potential_password_in_username.yml add JIRA --- detections/endpoint/potential_password_in_username.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/potential_password_in_username.yml b/detections/endpoint/potential_password_in_username.yml index 1aea399015..6b4097435d 100644 --- a/detections/endpoint/potential_password_in_username.yml +++ b/detections/endpoint/potential_password_in_username.yml @@ -51,7 +51,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud security_domain: access - manual_test: Due to an existing bug with eventtypes/tags in the splunk-add-on-for-unix-and-linux TA, this detection does not work with the latest version of the TA 10.0.0. You can refer to the following link for more information - https://github.com/splunk/splunk-add-on-for-unix-and-linux/issues/608. This detection works as expected with TAs prior to 10.0.0. + manual_test: Due to an existing bug with eventtypes/tags in the splunk-add-on-for-unix-and-linux TA, this detection does not work with the latest version of the TA 10.0.0. You can refer to the following link for more information - https://splunk.atlassian.net/browse/ADDON-81872. This detection works as expected with TAs prior to 10.0.0. tests: - name: True Positive Test attack_data: