mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
fix env typo in macros
This commit is contained in:
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: source=ActiveDirectory
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: admon
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=aws:cloudtrail:lake
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: amazon_security_lake
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="aws:cloudwatchlogs:eks"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: aws_cloudwatchlogs_eks
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=aws:config
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: aws_config
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="aws:description"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: aws_description
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=aws:s3:accesslogs
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: aws_s3_accesslogs
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="aws:securityhub:finding"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: aws_securityhub_finding
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="aws:securityhub:firehose"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: aws_securityhub_firehose
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=mscs:azure:audit
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: azure_audit
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=azure:monitor:aad
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: azure_monitor_aad
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=mscs:azure:eventhub
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: azuread
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype = PwSh:bootloader
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: bootloader_inventory
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: (source=XmlWinEventLog:Microsoft-Windows-CAPI2/Operational)
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: capi2_operational
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: (source=XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational OR source=XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational)
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: certificateservices_lifecycle
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=circleci
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: circleci
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: eventtype=cisco_ios
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: cisco_networks
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=aws:cloudtrail
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: cloudtrail
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype="aws:cloudwatchlogs:eks"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: cloudwatch_eks
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype=aws:cloudwatchlogs:vpcflow
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: cloudwatch_vpc
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=aws:cloudwatchlogs:vpcflow
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: cloudwatchlogs_vpcflow
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=crowdstrike:identities
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: crowdstrike_identities
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="CrowdStrike:Event:Streams:JSON"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: crowdstrike_stream
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="crushftp:sessionlogs"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: crushftp
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=PwSh:DriverInventory
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: driverinventory
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="MSWindows:IIS"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: exchange
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: index=netops sourcetype="f5:bigip:rogue"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: f5_bigip_rogue
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=aws:firehose:json
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: github
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype="google:gcp:pubsub:message"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: google_gcp_pubnet_message
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="google:gcp:pubsub:message"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: google_gcp_pubsub_message
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
definition: sourcetype=gsuite:calendar:json
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: gsuite_calendar
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
definition: sourcetype=gsuite:drive:json
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: gsuite_drive
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=gsuite:gmail:bigquery
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: gsuite_gmail
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: event.parameters{}.multiValue{} IN ("backup_code", "google_authenticator", "google_prompt", "idv_any_phone", "idv_preregistered_phone", "internal_two_factor", "knowledge_employee_id", "knowledge_preregistered_email", "login_location", "knowledge_preregistered_phone", "offline_otp", "security_key", "security_key_otp")
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: gws_login_mfa_methods
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=gws:reports:admin
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: gws_reports_admin
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=gws:reports:login
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: gws_reports_login
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="Pwsh:InstalledIISModules"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: iis_get_webglobalmodule
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="IIS:Configuration:Operational"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: iis_operational_logs
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=ivanti_vtm_audit
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: ivanti_vtm_audit
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: source="kubernetes"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: kube_audit
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype="kube:container:falco"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: kube_container_falco
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=kube:objects:events
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: kube_objects_events
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype=mscs:storage:blob:json
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: kubernetes_azure
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype=kube:container:controller
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: kubernetes_container_controller
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: index=kubernetes_metrics
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: kubernetes_metrics
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="linux:audit"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: linux_auditd
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: 'type=EXECVE | eval relevant_fields=if(type="EXECVE", "", relevant_fields) | foreach a* [eval relevant_fields=if(type="EXECVE", mvappend(relevant_fields, ''<<FIELD>>''), relevant_fields)] | eval process_exec=if(type="EXECVE", mvjoin(relevant_fields, " "), process_exec) | eval process_exec=if(type="EXECVE", trim(process_exec), process_exec)'
|
||||
description: customer specific splunk configurations to normalized auditd PROCTITLE type to recover process commandline.
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: linux_auditd_normalized_execve_process
|
||||
@@ -2,5 +2,5 @@ definition: 'type=PROCTITLE | eval normalized_proctitle_delimiter = if(type=="PR
|
||||
| eval normalized_proctitle_delimiter = if(type=="PROCTITLE" AND isnotnull(proctitle), if(match(normalized_proctitle_delimiter,"^[0-9A-F]+$"), replace(normalized_proctitle_delimiter, "00", "20"),normalized_proctitle_delimiter),null())
|
||||
| eval process_exec = if(match(normalized_proctitle_delimiter,"^[0-9A-F]+$"),urldecode(replace(normalized_proctitle_delimiter,"([0-9A-F]{2})","%\1")),normalized_proctitle_delimiter)'
|
||||
description: customer specific splunk configurations to normalized auditd PROCTITLE type to recover process commandline.
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: linux_auditd_normalized_proctitle_process
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: index=unix
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: linux_hosts
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: (Processes.process_name IN ("sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh", "tcsh", "ion", "eshell"))
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: linux_shells
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="sftp_server_logs"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: moveit_sftp_logs
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=ms365:defender:incident:alerts
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: ms365_defender_incident_alerts
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: source="WinEventLog:Microsoft-Windows-Windows Defender/Operational"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: ms_defender
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=ms:defender:atp:alerts
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: ms_defender_atp_alerts
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=MSExchange:management
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: msexchange_management
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="netbackup_logs"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: netbackup
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype=XmlWinEventLog:Microsoft-Windows-NTLM/Operational OR source=XmlWinEventLog:Microsoft-Windows-NTLM/Operational
|
||||
description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: ntlm_audit
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=o365:graph:api
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: o365_graph
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=o365:management:activity
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: o365_management_activity
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: eventtype=okta_log OR sourcetype = "OktaIM2:log"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: okta
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=osquery:results
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: osquery_macro
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: eventtype="osquery-process"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: osquery_process
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="papercutng"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: papercutng
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: source=PINGID
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: pingid
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational")
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: powershell
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: source="wineventlog:microsoft-windows-printservice/operational" OR source="WinEventLog:Microsoft-Windows-PrintService/Admin"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: printservice
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: source="WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: remoteconnectionmanager
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: index=risk
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: risk_index
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
definition: sourcetype=aws:s3:accesslogs
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: s3_accesslogs
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=stream:dns
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: stream_dns
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=stream:http
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: stream_http
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=stream:tcp
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: stream_tcp
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="PwSh:SubjectInterfacePackage"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: subjectinterfacepackage
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=suricata
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: suricata
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: sysmon
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: (Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=sh.exe OR Processes.process_name=bash.exe OR Processes.process_name=wscript.exe OR Processes.process_name=cscript.exe)
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: windows_shells
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: eventtype=wineventlog_security OR Channel=security OR source=XmlWinEventLog:Security
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: wineventlog_security
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: eventtype=wineventlog_system
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: wineventlog_system
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: (source="XmlWinEventLog:Microsoft-Windows-TaskScheduler/Operational" OR source="WinEventLog:Microsoft-Windows-TaskScheduler/Operational")
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: wineventlog_task_scheduler
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="wineventlog:microsoft-windows-wmi-activity/operational"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: wmi
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: index=zeek sourcetype="zeek:rpc:json"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: zeek_rpc
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: index=zeek sourcetype="zeek:ssl:json"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: zeek_ssl
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype="zeek:x509:json"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: zeek_x509
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
definition: source=zscaler sourcetype=zscalernss-web
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: zscaler_proxy
|
||||
|
||||
Reference in New Issue
Block a user