mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
update message formatting
This commit is contained in:
+1
-1
@@ -51,7 +51,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: Suspicious SSL certificate fingerprint ($SSL_CertFingerprint$) used in connections [ ListingReason: $Reasons$ ]
|
||||
message: Suspicious SSL certificate fingerprint - [$SSL_CertFingerprint$] used in connections [ListingReason - $Reasons$] from $src_ip$
|
||||
risk_objects:
|
||||
- field: src_ip
|
||||
type: system
|
||||
|
||||
Reference in New Issue
Block a user