fix env typo in macros

This commit is contained in:
Nasreddine Bencherchali
2024-11-26 23:43:48 +01:00
parent 0d45a7a5c0
commit d4aed3d50c
83 changed files with 83 additions and 83 deletions
+1 -1
View File
@@ -1,4 +1,4 @@
definition: source=ActiveDirectory
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: admon
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=aws:cloudtrail:lake
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: amazon_security_lake
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="aws:cloudwatchlogs:eks"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: aws_cloudwatchlogs_eks
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=aws:config
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: aws_config
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="aws:description"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: aws_description
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=aws:s3:accesslogs
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: aws_s3_accesslogs
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="aws:securityhub:finding"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: aws_securityhub_finding
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="aws:securityhub:firehose"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: aws_securityhub_firehose
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=mscs:azure:audit
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: azure_audit
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=azure:monitor:aad
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: azure_monitor_aad
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=mscs:azure:eventhub
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: azuread
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype = PwSh:bootloader
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: bootloader_inventory
+1 -1
View File
@@ -1,4 +1,4 @@
definition: (source=XmlWinEventLog:Microsoft-Windows-CAPI2/Operational)
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: capi2_operational
+1 -1
View File
@@ -1,4 +1,4 @@
definition: (source=XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational OR source=XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational)
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: certificateservices_lifecycle
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=circleci
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: circleci
+1 -1
View File
@@ -1,4 +1,4 @@
definition: eventtype=cisco_ios
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: cisco_networks
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=aws:cloudtrail
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: cloudtrail
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype="aws:cloudwatchlogs:eks"
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environment.
name: cloudwatch_eks
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype=aws:cloudwatchlogs:vpcflow
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment.
name: cloudwatch_vpc
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=aws:cloudwatchlogs:vpcflow
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: cloudwatchlogs_vpcflow
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=crowdstrike:identities
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: crowdstrike_identities
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="CrowdStrike:Event:Streams:JSON"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: crowdstrike_stream
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="crushftp:sessionlogs"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: crushftp
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=PwSh:DriverInventory
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: driverinventory
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="MSWindows:IIS"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: exchange
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=netops sourcetype="f5:bigip:rogue"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: f5_bigip_rogue
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=aws:firehose:json
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: github
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype="google:gcp:pubsub:message"
description: customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environment.
name: google_gcp_pubnet_message
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="google:gcp:pubsub:message"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: google_gcp_pubsub_message
+1 -1
View File
@@ -1,5 +1,5 @@
definition: sourcetype=gsuite:calendar:json
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: gsuite_calendar
+1 -1
View File
@@ -1,5 +1,5 @@
definition: sourcetype=gsuite:drive:json
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: gsuite_drive
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=gsuite:gmail:bigquery
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: gsuite_gmail
+1 -1
View File
@@ -1,4 +1,4 @@
definition: event.parameters{}.multiValue{} IN ("backup_code", "google_authenticator", "google_prompt", "idv_any_phone", "idv_preregistered_phone", "internal_two_factor", "knowledge_employee_id", "knowledge_preregistered_email", "login_location", "knowledge_preregistered_phone", "offline_otp", "security_key", "security_key_otp")
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: gws_login_mfa_methods
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=gws:reports:admin
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: gws_reports_admin
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=gws:reports:login
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: gws_reports_login
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="Pwsh:InstalledIISModules"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: iis_get_webglobalmodule
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="IIS:Configuration:Operational"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: iis_operational_logs
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=ivanti_vtm_audit
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: ivanti_vtm_audit
+1 -1
View File
@@ -1,3 +1,3 @@
definition: source="kubernetes"
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environment.
name: kube_audit
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype="kube:container:falco"
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environment.
name: kube_container_falco
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=kube:objects:events
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: kube_objects_events
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype=mscs:storage:blob:json
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environment.
name: kubernetes_azure
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype=kube:container:controller
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environment.
name: kubernetes_container_controller
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=kubernetes_metrics
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: kubernetes_metrics
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="linux:audit"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: linux_auditd
@@ -1,4 +1,4 @@
definition: 'type=EXECVE | eval relevant_fields=if(type="EXECVE", "", relevant_fields) | foreach a* [eval relevant_fields=if(type="EXECVE", mvappend(relevant_fields, ''<<FIELD>>''), relevant_fields)] | eval process_exec=if(type="EXECVE", mvjoin(relevant_fields, " "), process_exec) | eval process_exec=if(type="EXECVE", trim(process_exec), process_exec)'
description: customer specific splunk configurations to normalized auditd PROCTITLE type to recover process commandline.
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: linux_auditd_normalized_execve_process
@@ -2,5 +2,5 @@ definition: 'type=PROCTITLE | eval normalized_proctitle_delimiter = if(type=="PR
| eval normalized_proctitle_delimiter = if(type=="PROCTITLE" AND isnotnull(proctitle), if(match(normalized_proctitle_delimiter,"^[0-9A-F]+$"), replace(normalized_proctitle_delimiter, "00", "20"),normalized_proctitle_delimiter),null())
| eval process_exec = if(match(normalized_proctitle_delimiter,"^[0-9A-F]+$"),urldecode(replace(normalized_proctitle_delimiter,"([0-9A-F]{2})","%\1")),normalized_proctitle_delimiter)'
description: customer specific splunk configurations to normalized auditd PROCTITLE type to recover process commandline.
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: linux_auditd_normalized_proctitle_process
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=unix
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: linux_hosts
+1 -1
View File
@@ -1,4 +1,4 @@
definition: (Processes.process_name IN ("sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh", "tcsh", "ion", "eshell"))
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: linux_shells
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="sftp_server_logs"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: moveit_sftp_logs
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=ms365:defender:incident:alerts
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: ms365_defender_incident_alerts
+1 -1
View File
@@ -1,4 +1,4 @@
definition: source="WinEventLog:Microsoft-Windows-Windows Defender/Operational"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: ms_defender
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=ms:defender:atp:alerts
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: ms_defender_atp_alerts
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=MSExchange:management
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: msexchange_management
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="netbackup_logs"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: netbackup
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype=XmlWinEventLog:Microsoft-Windows-NTLM/Operational OR source=XmlWinEventLog:Microsoft-Windows-NTLM/Operational
description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment.
name: ntlm_audit
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=o365:graph:api
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: o365_graph
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=o365:management:activity
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: o365_management_activity
+1 -1
View File
@@ -1,4 +1,4 @@
definition: eventtype=okta_log OR sourcetype = "OktaIM2:log"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: okta
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=osquery:results
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: osquery_macro
+1 -1
View File
@@ -1,4 +1,4 @@
definition: eventtype="osquery-process"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: osquery_process
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="papercutng"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: papercutng
+1 -1
View File
@@ -1,4 +1,4 @@
definition: source=PINGID
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: pingid
+1 -1
View File
@@ -1,4 +1,4 @@
definition: (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational")
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: powershell
+1 -1
View File
@@ -1,4 +1,4 @@
definition: source="wineventlog:microsoft-windows-printservice/operational" OR source="WinEventLog:Microsoft-Windows-PrintService/Admin"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: printservice
+1 -1
View File
@@ -1,4 +1,4 @@
definition: source="WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: remoteconnectionmanager
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=risk
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: risk_index
+1 -1
View File
@@ -1,3 +1,3 @@
definition: sourcetype=aws:s3:accesslogs
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent.
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment.
name: s3_accesslogs
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=stream:dns
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: stream_dns
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=stream:http
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: stream_http
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=stream:tcp
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: stream_tcp
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="PwSh:SubjectInterfacePackage"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: subjectinterfacepackage
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=suricata
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: suricata
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: sysmon
+1 -1
View File
@@ -1,4 +1,4 @@
definition: (Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=sh.exe OR Processes.process_name=bash.exe OR Processes.process_name=wscript.exe OR Processes.process_name=cscript.exe)
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: windows_shells
+1 -1
View File
@@ -1,4 +1,4 @@
definition: eventtype=wineventlog_security OR Channel=security OR source=XmlWinEventLog:Security
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: wineventlog_security
+1 -1
View File
@@ -1,4 +1,4 @@
definition: eventtype=wineventlog_system
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: wineventlog_system
+1 -1
View File
@@ -1,4 +1,4 @@
definition: (source="XmlWinEventLog:Microsoft-Windows-TaskScheduler/Operational" OR source="WinEventLog:Microsoft-Windows-TaskScheduler/Operational")
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: wineventlog_task_scheduler
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="wineventlog:microsoft-windows-wmi-activity/operational"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: wmi
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=zeek sourcetype="zeek:rpc:json"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: zeek_rpc
+1 -1
View File
@@ -1,4 +1,4 @@
definition: index=zeek sourcetype="zeek:ssl:json"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: zeek_ssl
+1 -1
View File
@@ -1,4 +1,4 @@
definition: sourcetype="zeek:x509:json"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: zeek_x509
+1 -1
View File
@@ -1,4 +1,4 @@
definition: source=zscaler sourcetype=zscalernss-web
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
Replace the macro definition with configurations for your Splunk Environment.
name: zscaler_proxy