diff --git a/macros/admon.yml b/macros/admon.yml index debd763e8b..e722dd2774 100644 --- a/macros/admon.yml +++ b/macros/admon.yml @@ -1,4 +1,4 @@ definition: source=ActiveDirectory description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: admon diff --git a/macros/amazon_security_lake.yml b/macros/amazon_security_lake.yml index bfdfa2962c..9b27aad2aa 100644 --- a/macros/amazon_security_lake.yml +++ b/macros/amazon_security_lake.yml @@ -1,4 +1,4 @@ definition: sourcetype=aws:cloudtrail:lake description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: amazon_security_lake diff --git a/macros/aws_cloudwatchlogs_eks.yml b/macros/aws_cloudwatchlogs_eks.yml index 712770fab9..8207e859ab 100644 --- a/macros/aws_cloudwatchlogs_eks.yml +++ b/macros/aws_cloudwatchlogs_eks.yml @@ -1,4 +1,4 @@ definition: sourcetype="aws:cloudwatchlogs:eks" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: aws_cloudwatchlogs_eks diff --git a/macros/aws_config.yml b/macros/aws_config.yml index c709c1e0a5..316654d944 100644 --- a/macros/aws_config.yml +++ b/macros/aws_config.yml @@ -1,4 +1,4 @@ definition: sourcetype=aws:config description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: aws_config diff --git a/macros/aws_description.yml b/macros/aws_description.yml index 223e3effaa..bd99a023fd 100644 --- a/macros/aws_description.yml +++ b/macros/aws_description.yml @@ -1,4 +1,4 @@ definition: sourcetype="aws:description" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: aws_description diff --git a/macros/aws_s3_accesslogs.yml b/macros/aws_s3_accesslogs.yml index 60aecdb081..c64a351dbc 100644 --- a/macros/aws_s3_accesslogs.yml +++ b/macros/aws_s3_accesslogs.yml @@ -1,4 +1,4 @@ definition: sourcetype=aws:s3:accesslogs description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: aws_s3_accesslogs diff --git a/macros/aws_securityhub_finding.yml b/macros/aws_securityhub_finding.yml index 2f19f0c2aa..790f334c3b 100644 --- a/macros/aws_securityhub_finding.yml +++ b/macros/aws_securityhub_finding.yml @@ -1,4 +1,4 @@ definition: sourcetype="aws:securityhub:finding" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: aws_securityhub_finding diff --git a/macros/aws_securityhub_firehose.yml b/macros/aws_securityhub_firehose.yml index b362424495..baa04804b5 100644 --- a/macros/aws_securityhub_firehose.yml +++ b/macros/aws_securityhub_firehose.yml @@ -1,4 +1,4 @@ definition: sourcetype="aws:securityhub:firehose" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: aws_securityhub_firehose diff --git a/macros/azure_audit.yml b/macros/azure_audit.yml index 80b295bfe4..a332860570 100644 --- a/macros/azure_audit.yml +++ b/macros/azure_audit.yml @@ -1,4 +1,4 @@ definition: sourcetype=mscs:azure:audit description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: azure_audit diff --git a/macros/azure_monitor_aad.yml b/macros/azure_monitor_aad.yml index 034411f4c3..9cb1066059 100644 --- a/macros/azure_monitor_aad.yml +++ b/macros/azure_monitor_aad.yml @@ -1,4 +1,4 @@ definition: sourcetype=azure:monitor:aad description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: azure_monitor_aad diff --git a/macros/azuread.yml b/macros/azuread.yml index bff933179e..c21f08c0ef 100644 --- a/macros/azuread.yml +++ b/macros/azuread.yml @@ -1,4 +1,4 @@ definition: sourcetype=mscs:azure:eventhub description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: azuread diff --git a/macros/bootloader_inventory.yml b/macros/bootloader_inventory.yml index 51a7eb40bc..0f8147364a 100644 --- a/macros/bootloader_inventory.yml +++ b/macros/bootloader_inventory.yml @@ -1,4 +1,4 @@ definition: sourcetype = PwSh:bootloader description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: bootloader_inventory \ No newline at end of file diff --git a/macros/capi2_operational.yml b/macros/capi2_operational.yml index 1a9daf3b16..926c576cf7 100644 --- a/macros/capi2_operational.yml +++ b/macros/capi2_operational.yml @@ -1,4 +1,4 @@ definition: (source=XmlWinEventLog:Microsoft-Windows-CAPI2/Operational) description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: capi2_operational \ No newline at end of file diff --git a/macros/certificateservices_lifecycle.yml b/macros/certificateservices_lifecycle.yml index 38a1f784ba..6991116bd2 100644 --- a/macros/certificateservices_lifecycle.yml +++ b/macros/certificateservices_lifecycle.yml @@ -1,4 +1,4 @@ definition: (source=XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational OR source=XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational) description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: certificateservices_lifecycle \ No newline at end of file diff --git a/macros/circleci.yml b/macros/circleci.yml index 800c7539d5..b770e6f881 100644 --- a/macros/circleci.yml +++ b/macros/circleci.yml @@ -1,4 +1,4 @@ definition: sourcetype=circleci description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: circleci \ No newline at end of file diff --git a/macros/cisco_networks.yml b/macros/cisco_networks.yml index 3c2e8c0a1e..d6c1e02e0e 100644 --- a/macros/cisco_networks.yml +++ b/macros/cisco_networks.yml @@ -1,4 +1,4 @@ definition: eventtype=cisco_ios description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: cisco_networks diff --git a/macros/cloudtrail.yml b/macros/cloudtrail.yml index bb4982174e..ed76aa0e00 100644 --- a/macros/cloudtrail.yml +++ b/macros/cloudtrail.yml @@ -1,4 +1,4 @@ definition: sourcetype=aws:cloudtrail description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: cloudtrail diff --git a/macros/cloudwatch_eks.yml b/macros/cloudwatch_eks.yml index 5a8dcca164..5801e2b9b8 100644 --- a/macros/cloudwatch_eks.yml +++ b/macros/cloudwatch_eks.yml @@ -1,3 +1,3 @@ definition: sourcetype="aws:cloudwatchlogs:eks" -description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environment. name: cloudwatch_eks diff --git a/macros/cloudwatch_vpc.yml b/macros/cloudwatch_vpc.yml index 1c8bd5d11b..c99f1b3da3 100644 --- a/macros/cloudwatch_vpc.yml +++ b/macros/cloudwatch_vpc.yml @@ -1,3 +1,3 @@ definition: sourcetype=aws:cloudwatchlogs:vpcflow -description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment. name: cloudwatch_vpc diff --git a/macros/cloudwatchlogs_vpcflow.yml b/macros/cloudwatchlogs_vpcflow.yml index d9dd3ac720..16d69675b7 100644 --- a/macros/cloudwatchlogs_vpcflow.yml +++ b/macros/cloudwatchlogs_vpcflow.yml @@ -1,4 +1,4 @@ definition: sourcetype=aws:cloudwatchlogs:vpcflow description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: cloudwatchlogs_vpcflow diff --git a/macros/crowdstrike_identities.yml b/macros/crowdstrike_identities.yml index 54b5b08dd9..13e417eb0f 100644 --- a/macros/crowdstrike_identities.yml +++ b/macros/crowdstrike_identities.yml @@ -1,4 +1,4 @@ definition: sourcetype=crowdstrike:identities description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: crowdstrike_identities \ No newline at end of file diff --git a/macros/crowdstrike_stream.yml b/macros/crowdstrike_stream.yml index 3237270c90..2354c8a199 100644 --- a/macros/crowdstrike_stream.yml +++ b/macros/crowdstrike_stream.yml @@ -1,4 +1,4 @@ definition: sourcetype="CrowdStrike:Event:Streams:JSON" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: crowdstrike_stream \ No newline at end of file diff --git a/macros/crushftp.yml b/macros/crushftp.yml index 884a1408e1..c996bc1430 100644 --- a/macros/crushftp.yml +++ b/macros/crushftp.yml @@ -1,4 +1,4 @@ definition: sourcetype="crushftp:sessionlogs" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: crushftp diff --git a/macros/driverinventory.yml b/macros/driverinventory.yml index ff6620cc20..082aca520a 100644 --- a/macros/driverinventory.yml +++ b/macros/driverinventory.yml @@ -1,4 +1,4 @@ definition: sourcetype=PwSh:DriverInventory description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: driverinventory \ No newline at end of file diff --git a/macros/exchange.yml b/macros/exchange.yml index e605f9007c..c32c147a16 100644 --- a/macros/exchange.yml +++ b/macros/exchange.yml @@ -1,4 +1,4 @@ definition: sourcetype="MSWindows:IIS" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: exchange \ No newline at end of file diff --git a/macros/f5_bigip_rogue.yml b/macros/f5_bigip_rogue.yml index 265a320d9e..4c80756aaa 100644 --- a/macros/f5_bigip_rogue.yml +++ b/macros/f5_bigip_rogue.yml @@ -1,4 +1,4 @@ definition: index=netops sourcetype="f5:bigip:rogue" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: f5_bigip_rogue \ No newline at end of file diff --git a/macros/github.yml b/macros/github.yml index 5064aa92ed..cd7c2949df 100644 --- a/macros/github.yml +++ b/macros/github.yml @@ -1,4 +1,4 @@ definition: sourcetype=aws:firehose:json description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: github \ No newline at end of file diff --git a/macros/google_gcp_pubnet_message.yml b/macros/google_gcp_pubnet_message.yml index e8de3e401e..a827bea756 100644 --- a/macros/google_gcp_pubnet_message.yml +++ b/macros/google_gcp_pubnet_message.yml @@ -1,3 +1,3 @@ definition: sourcetype="google:gcp:pubsub:message" -description: customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environment. name: google_gcp_pubnet_message diff --git a/macros/google_gcp_pubsub_message.yml b/macros/google_gcp_pubsub_message.yml index e040e3cfa3..9748f575e9 100644 --- a/macros/google_gcp_pubsub_message.yml +++ b/macros/google_gcp_pubsub_message.yml @@ -1,4 +1,4 @@ definition: sourcetype="google:gcp:pubsub:message" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: google_gcp_pubsub_message diff --git a/macros/gsuite_calendar.yml b/macros/gsuite_calendar.yml index a4ccb0c364..2153cea730 100644 --- a/macros/gsuite_calendar.yml +++ b/macros/gsuite_calendar.yml @@ -1,5 +1,5 @@ definition: sourcetype=gsuite:calendar:json description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: gsuite_calendar diff --git a/macros/gsuite_drive.yml b/macros/gsuite_drive.yml index 6c00f68a75..87e6512e46 100644 --- a/macros/gsuite_drive.yml +++ b/macros/gsuite_drive.yml @@ -1,5 +1,5 @@ definition: sourcetype=gsuite:drive:json description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: gsuite_drive diff --git a/macros/gsuite_gmail.yml b/macros/gsuite_gmail.yml index 21ed20bfc4..d6db69448d 100644 --- a/macros/gsuite_gmail.yml +++ b/macros/gsuite_gmail.yml @@ -1,4 +1,4 @@ definition: sourcetype=gsuite:gmail:bigquery description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: gsuite_gmail \ No newline at end of file diff --git a/macros/gws_login_mfa_methods.yml b/macros/gws_login_mfa_methods.yml index a5069104aa..174731fe52 100644 --- a/macros/gws_login_mfa_methods.yml +++ b/macros/gws_login_mfa_methods.yml @@ -1,4 +1,4 @@ definition: event.parameters{}.multiValue{} IN ("backup_code", "google_authenticator", "google_prompt", "idv_any_phone", "idv_preregistered_phone", "internal_two_factor", "knowledge_employee_id", "knowledge_preregistered_email", "login_location", "knowledge_preregistered_phone", "offline_otp", "security_key", "security_key_otp") description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: gws_login_mfa_methods diff --git a/macros/gws_reports_admin.yml b/macros/gws_reports_admin.yml index 2de3cbb395..5de8cdbc03 100644 --- a/macros/gws_reports_admin.yml +++ b/macros/gws_reports_admin.yml @@ -1,4 +1,4 @@ definition: sourcetype=gws:reports:admin description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: gws_reports_admin diff --git a/macros/gws_reports_login.yml b/macros/gws_reports_login.yml index 5e759542e7..8bd0e68357 100644 --- a/macros/gws_reports_login.yml +++ b/macros/gws_reports_login.yml @@ -1,4 +1,4 @@ definition: sourcetype=gws:reports:login description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: gws_reports_login diff --git a/macros/iis_get_webglobalmodule.yml b/macros/iis_get_webglobalmodule.yml index 110e57a12d..47e1702308 100644 --- a/macros/iis_get_webglobalmodule.yml +++ b/macros/iis_get_webglobalmodule.yml @@ -1,4 +1,4 @@ definition: sourcetype="Pwsh:InstalledIISModules" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: iis_get_webglobalmodule \ No newline at end of file diff --git a/macros/iis_operational_logs.yml b/macros/iis_operational_logs.yml index b2de785850..fd901958e8 100644 --- a/macros/iis_operational_logs.yml +++ b/macros/iis_operational_logs.yml @@ -1,4 +1,4 @@ definition: sourcetype="IIS:Configuration:Operational" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: iis_operational_logs \ No newline at end of file diff --git a/macros/ivanti_vtm_audit.yml b/macros/ivanti_vtm_audit.yml index ec6732832d..4d5559fd83 100644 --- a/macros/ivanti_vtm_audit.yml +++ b/macros/ivanti_vtm_audit.yml @@ -1,4 +1,4 @@ definition: sourcetype=ivanti_vtm_audit description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: ivanti_vtm_audit diff --git a/macros/kube_audit.yml b/macros/kube_audit.yml index bd6dcec535..7b30be7cfc 100644 --- a/macros/kube_audit.yml +++ b/macros/kube_audit.yml @@ -1,3 +1,3 @@ definition: source="kubernetes" -description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environment. name: kube_audit diff --git a/macros/kube_container_falco.yml b/macros/kube_container_falco.yml index 08ebaa263d..095d0fcd4d 100644 --- a/macros/kube_container_falco.yml +++ b/macros/kube_container_falco.yml @@ -1,3 +1,3 @@ definition: sourcetype="kube:container:falco" -description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes audit data. Replace the macro definition with configurations for your Splunk Environment. name: kube_container_falco diff --git a/macros/kube_objects_events.yml b/macros/kube_objects_events.yml index ae4dd70960..90914b3120 100644 --- a/macros/kube_objects_events.yml +++ b/macros/kube_objects_events.yml @@ -1,4 +1,4 @@ definition: sourcetype=kube:objects:events description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: kube_objects_events diff --git a/macros/kubernetes_azure.yml b/macros/kubernetes_azure.yml index 2a23d362e5..5cf5461397 100644 --- a/macros/kubernetes_azure.yml +++ b/macros/kubernetes_azure.yml @@ -1,3 +1,3 @@ definition: sourcetype=mscs:storage:blob:json -description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environment. name: kubernetes_azure diff --git a/macros/kubernetes_container_controller.yml b/macros/kubernetes_container_controller.yml index 29793801b8..4e2fa20d99 100644 --- a/macros/kubernetes_container_controller.yml +++ b/macros/kubernetes_container_controller.yml @@ -1,3 +1,3 @@ definition: sourcetype=kube:container:controller -description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environment. name: kubernetes_container_controller diff --git a/macros/kubernetes_metrics.yml b/macros/kubernetes_metrics.yml index 8c795e1cbc..955a5c3994 100644 --- a/macros/kubernetes_metrics.yml +++ b/macros/kubernetes_metrics.yml @@ -1,4 +1,4 @@ definition: index=kubernetes_metrics description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: kubernetes_metrics diff --git a/macros/linux_auditd.yml b/macros/linux_auditd.yml index 70ce2b76cd..66f941fb15 100644 --- a/macros/linux_auditd.yml +++ b/macros/linux_auditd.yml @@ -1,4 +1,4 @@ definition: sourcetype="linux:audit" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: linux_auditd \ No newline at end of file diff --git a/macros/linux_auditd_normalized_execve_process.yml b/macros/linux_auditd_normalized_execve_process.yml index 83f885f803..ac9848ade0 100644 --- a/macros/linux_auditd_normalized_execve_process.yml +++ b/macros/linux_auditd_normalized_execve_process.yml @@ -1,4 +1,4 @@ definition: 'type=EXECVE | eval relevant_fields=if(type="EXECVE", "", relevant_fields) | foreach a* [eval relevant_fields=if(type="EXECVE", mvappend(relevant_fields, ''<>''), relevant_fields)] | eval process_exec=if(type="EXECVE", mvjoin(relevant_fields, " "), process_exec) | eval process_exec=if(type="EXECVE", trim(process_exec), process_exec)' description: customer specific splunk configurations to normalized auditd PROCTITLE type to recover process commandline. - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: linux_auditd_normalized_execve_process \ No newline at end of file diff --git a/macros/linux_auditd_normalized_proctitle_process.yml b/macros/linux_auditd_normalized_proctitle_process.yml index 999b133614..d49c62fa99 100644 --- a/macros/linux_auditd_normalized_proctitle_process.yml +++ b/macros/linux_auditd_normalized_proctitle_process.yml @@ -2,5 +2,5 @@ definition: 'type=PROCTITLE | eval normalized_proctitle_delimiter = if(type=="PR | eval normalized_proctitle_delimiter = if(type=="PROCTITLE" AND isnotnull(proctitle), if(match(normalized_proctitle_delimiter,"^[0-9A-F]+$"), replace(normalized_proctitle_delimiter, "00", "20"),normalized_proctitle_delimiter),null()) | eval process_exec = if(match(normalized_proctitle_delimiter,"^[0-9A-F]+$"),urldecode(replace(normalized_proctitle_delimiter,"([0-9A-F]{2})","%\1")),normalized_proctitle_delimiter)' description: customer specific splunk configurations to normalized auditd PROCTITLE type to recover process commandline. - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: linux_auditd_normalized_proctitle_process \ No newline at end of file diff --git a/macros/linux_hosts.yml b/macros/linux_hosts.yml index 4daeaf4d56..a71e63f79f 100644 --- a/macros/linux_hosts.yml +++ b/macros/linux_hosts.yml @@ -1,4 +1,4 @@ definition: index=unix description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: linux_hosts \ No newline at end of file diff --git a/macros/linux_shells.yml b/macros/linux_shells.yml index 9dae4051c2..bc3d2f01d1 100644 --- a/macros/linux_shells.yml +++ b/macros/linux_shells.yml @@ -1,4 +1,4 @@ definition: (Processes.process_name IN ("sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh", "tcsh", "ion", "eshell")) description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: linux_shells diff --git a/macros/moveit_sftp_logs.yml b/macros/moveit_sftp_logs.yml index 0cae0bd423..282ac0aee7 100644 --- a/macros/moveit_sftp_logs.yml +++ b/macros/moveit_sftp_logs.yml @@ -1,4 +1,4 @@ definition: sourcetype="sftp_server_logs" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: moveit_sftp_logs \ No newline at end of file diff --git a/macros/ms365_defender_incident_alerts.yml b/macros/ms365_defender_incident_alerts.yml index a96ee5eec5..6cddd1cea7 100644 --- a/macros/ms365_defender_incident_alerts.yml +++ b/macros/ms365_defender_incident_alerts.yml @@ -1,4 +1,4 @@ definition: sourcetype=ms365:defender:incident:alerts description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: ms365_defender_incident_alerts diff --git a/macros/ms_defender.yml b/macros/ms_defender.yml index b67007aa2c..ad8e782902 100644 --- a/macros/ms_defender.yml +++ b/macros/ms_defender.yml @@ -1,4 +1,4 @@ definition: source="WinEventLog:Microsoft-Windows-Windows Defender/Operational" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: ms_defender diff --git a/macros/ms_defender_atp_alerts.yml b/macros/ms_defender_atp_alerts.yml index ab5d3bce11..ad3a4ac824 100644 --- a/macros/ms_defender_atp_alerts.yml +++ b/macros/ms_defender_atp_alerts.yml @@ -1,4 +1,4 @@ definition: sourcetype=ms:defender:atp:alerts description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: ms_defender_atp_alerts \ No newline at end of file diff --git a/macros/msexchange_management.yml b/macros/msexchange_management.yml index fe14bd287d..f235a6b1f0 100644 --- a/macros/msexchange_management.yml +++ b/macros/msexchange_management.yml @@ -1,4 +1,4 @@ definition: sourcetype=MSExchange:management description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: msexchange_management \ No newline at end of file diff --git a/macros/netbackup.yml b/macros/netbackup.yml index 2021f88e1b..ef2d10523c 100644 --- a/macros/netbackup.yml +++ b/macros/netbackup.yml @@ -1,4 +1,4 @@ definition: sourcetype="netbackup_logs" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: netbackup diff --git a/macros/ntlm_audit.yml b/macros/ntlm_audit.yml index 56f41c7934..33b00a2515 100644 --- a/macros/ntlm_audit.yml +++ b/macros/ntlm_audit.yml @@ -1,3 +1,3 @@ definition: sourcetype=XmlWinEventLog:Microsoft-Windows-NTLM/Operational OR source=XmlWinEventLog:Microsoft-Windows-NTLM/Operational -description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. +description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment. name: ntlm_audit \ No newline at end of file diff --git a/macros/o365_graph.yml b/macros/o365_graph.yml index 96b26e777b..aa411a74fa 100644 --- a/macros/o365_graph.yml +++ b/macros/o365_graph.yml @@ -1,4 +1,4 @@ definition: sourcetype=o365:graph:api description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: o365_graph diff --git a/macros/o365_management_activity.yml b/macros/o365_management_activity.yml index 75f3331639..dc0f2d52b1 100644 --- a/macros/o365_management_activity.yml +++ b/macros/o365_management_activity.yml @@ -1,4 +1,4 @@ definition: sourcetype=o365:management:activity description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: o365_management_activity diff --git a/macros/okta.yml b/macros/okta.yml index fb9dab0b3b..10e753fe84 100644 --- a/macros/okta.yml +++ b/macros/okta.yml @@ -1,4 +1,4 @@ definition: eventtype=okta_log OR sourcetype = "OktaIM2:log" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: okta diff --git a/macros/osquery_macro.yml b/macros/osquery_macro.yml index 32473363ff..690b08f83f 100644 --- a/macros/osquery_macro.yml +++ b/macros/osquery_macro.yml @@ -1,4 +1,4 @@ definition: sourcetype=osquery:results description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: osquery_macro \ No newline at end of file diff --git a/macros/osquery_process.yml b/macros/osquery_process.yml index ea972a976f..1b9167cdfd 100644 --- a/macros/osquery_process.yml +++ b/macros/osquery_process.yml @@ -1,4 +1,4 @@ definition: eventtype="osquery-process" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: osquery_process \ No newline at end of file diff --git a/macros/papercutng.yml b/macros/papercutng.yml index 011e867914..167e3cff5e 100644 --- a/macros/papercutng.yml +++ b/macros/papercutng.yml @@ -1,4 +1,4 @@ definition: sourcetype="papercutng" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: papercutng diff --git a/macros/pingid.yml b/macros/pingid.yml index aa289396fe..e7b615795e 100644 --- a/macros/pingid.yml +++ b/macros/pingid.yml @@ -1,4 +1,4 @@ definition: source=PINGID description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: pingid \ No newline at end of file diff --git a/macros/powershell.yml b/macros/powershell.yml index d6b8f842d3..ab249a05ad 100644 --- a/macros/powershell.yml +++ b/macros/powershell.yml @@ -1,4 +1,4 @@ definition: (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational") description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: powershell diff --git a/macros/printservice.yml b/macros/printservice.yml index 02f97ed5b5..da9ab4db46 100644 --- a/macros/printservice.yml +++ b/macros/printservice.yml @@ -1,4 +1,4 @@ definition: source="wineventlog:microsoft-windows-printservice/operational" OR source="WinEventLog:Microsoft-Windows-PrintService/Admin" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: printservice diff --git a/macros/remoteconnectionmanager.yml b/macros/remoteconnectionmanager.yml index 325ecd2e01..69ac35f746 100644 --- a/macros/remoteconnectionmanager.yml +++ b/macros/remoteconnectionmanager.yml @@ -1,4 +1,4 @@ definition: source="WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: remoteconnectionmanager \ No newline at end of file diff --git a/macros/risk_index.yml b/macros/risk_index.yml index e8194460d6..17409e506a 100644 --- a/macros/risk_index.yml +++ b/macros/risk_index.yml @@ -1,4 +1,4 @@ definition: index=risk description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: risk_index diff --git a/macros/s3_accesslogs.yml b/macros/s3_accesslogs.yml index 5bf66bb4e5..53ff9de5ec 100644 --- a/macros/s3_accesslogs.yml +++ b/macros/s3_accesslogs.yml @@ -1,3 +1,3 @@ definition: sourcetype=aws:s3:accesslogs -description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent. +description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment. name: s3_accesslogs diff --git a/macros/stream_dns.yml b/macros/stream_dns.yml index c43f3a18cf..6f9b52e6f3 100644 --- a/macros/stream_dns.yml +++ b/macros/stream_dns.yml @@ -1,4 +1,4 @@ definition: sourcetype=stream:dns description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: stream_dns \ No newline at end of file diff --git a/macros/stream_http.yml b/macros/stream_http.yml index 3f01a15760..3cfed7afd1 100644 --- a/macros/stream_http.yml +++ b/macros/stream_http.yml @@ -1,4 +1,4 @@ definition: sourcetype=stream:http description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: stream_http diff --git a/macros/stream_tcp.yml b/macros/stream_tcp.yml index 2a5e359240..7f524b958c 100644 --- a/macros/stream_tcp.yml +++ b/macros/stream_tcp.yml @@ -1,4 +1,4 @@ definition: sourcetype=stream:tcp description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: stream_tcp \ No newline at end of file diff --git a/macros/subjectinterfacepackage.yml b/macros/subjectinterfacepackage.yml index 0cad38ff22..5c4e310625 100644 --- a/macros/subjectinterfacepackage.yml +++ b/macros/subjectinterfacepackage.yml @@ -1,4 +1,4 @@ definition: sourcetype="PwSh:SubjectInterfacePackage" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: subjectinterfacepackage \ No newline at end of file diff --git a/macros/suricata.yml b/macros/suricata.yml index 95e3c453ad..917e989a80 100644 --- a/macros/suricata.yml +++ b/macros/suricata.yml @@ -1,4 +1,4 @@ definition: sourcetype=suricata description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: suricata diff --git a/macros/sysmon.yml b/macros/sysmon.yml index 17fdbd53e0..d9667ff88a 100644 --- a/macros/sysmon.yml +++ b/macros/sysmon.yml @@ -1,4 +1,4 @@ definition: sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: sysmon diff --git a/macros/windows_shells.yml b/macros/windows_shells.yml index b7f6a287d6..ed6902e1d9 100644 --- a/macros/windows_shells.yml +++ b/macros/windows_shells.yml @@ -1,4 +1,4 @@ definition: (Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=sh.exe OR Processes.process_name=bash.exe OR Processes.process_name=wscript.exe OR Processes.process_name=cscript.exe) description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: windows_shells diff --git a/macros/wineventlog_security.yml b/macros/wineventlog_security.yml index 65bed12450..e307166965 100644 --- a/macros/wineventlog_security.yml +++ b/macros/wineventlog_security.yml @@ -1,4 +1,4 @@ definition: eventtype=wineventlog_security OR Channel=security OR source=XmlWinEventLog:Security description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: wineventlog_security diff --git a/macros/wineventlog_system.yml b/macros/wineventlog_system.yml index d6c9a4b88b..779e36e948 100644 --- a/macros/wineventlog_system.yml +++ b/macros/wineventlog_system.yml @@ -1,4 +1,4 @@ definition: eventtype=wineventlog_system description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: wineventlog_system diff --git a/macros/wineventlog_task_scheduler.yml b/macros/wineventlog_task_scheduler.yml index d548b6f987..affd3842e4 100644 --- a/macros/wineventlog_task_scheduler.yml +++ b/macros/wineventlog_task_scheduler.yml @@ -1,4 +1,4 @@ definition: (source="XmlWinEventLog:Microsoft-Windows-TaskScheduler/Operational" OR source="WinEventLog:Microsoft-Windows-TaskScheduler/Operational") description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: wineventlog_task_scheduler \ No newline at end of file diff --git a/macros/wmi.yml b/macros/wmi.yml index 9769d5c79d..155d964ba5 100644 --- a/macros/wmi.yml +++ b/macros/wmi.yml @@ -1,4 +1,4 @@ definition: sourcetype="wineventlog:microsoft-windows-wmi-activity/operational" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: wmi diff --git a/macros/zeek_rpc.yml b/macros/zeek_rpc.yml index 14e7c7adcc..373581dceb 100644 --- a/macros/zeek_rpc.yml +++ b/macros/zeek_rpc.yml @@ -1,4 +1,4 @@ definition: index=zeek sourcetype="zeek:rpc:json" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: zeek_rpc diff --git a/macros/zeek_ssl.yml b/macros/zeek_ssl.yml index 76e061ab48..258e60a703 100644 --- a/macros/zeek_ssl.yml +++ b/macros/zeek_ssl.yml @@ -1,4 +1,4 @@ definition: index=zeek sourcetype="zeek:ssl:json" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: zeek_ssl diff --git a/macros/zeek_x509.yml b/macros/zeek_x509.yml index 243f259ac0..e61759c6ab 100644 --- a/macros/zeek_x509.yml +++ b/macros/zeek_x509.yml @@ -1,4 +1,4 @@ definition: sourcetype="zeek:x509:json" description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: zeek_x509 diff --git a/macros/zscaler_proxy.yml b/macros/zscaler_proxy.yml index 81e1542bbe..96b46cb900 100644 --- a/macros/zscaler_proxy.yml +++ b/macros/zscaler_proxy.yml @@ -1,4 +1,4 @@ definition: source=zscaler sourcetype=zscalernss-web description: customer specific splunk configurations(eg- index, source, sourcetype). - Replace the macro definition with configurations for your Splunk Environmnent. + Replace the macro definition with configurations for your Splunk Environment. name: zscaler_proxy