Commit Graph

978 Commits

Author SHA1 Message Date
divious1 b5c461abd3 updating error 2019-10-14 14:06:53 -04:00
bpatel 6b013d2531 adding dashboard updates 2019-10-11 14:53:47 -07:00
bpatel d11440ff37 yeild null results when no detection results found 2019-10-10 17:58:37 -07:00
bpatel f97cdc34d7 detection dashboard update 2019-10-10 17:43:12 -07:00
bpatel 191c68f106 Merge branch 'run_detections' of https://github.com/splunk/security-content into run_detections 2019-10-10 17:36:27 -07:00
bpatel 7fe8328a8d adding a macro to format the detect results 2019-10-10 17:36:15 -07:00
divious1 38d430cfd3 working version of investigate 2019-10-10 16:38:33 -05:00
bpatel 9755770513 detect checks 2019-10-10 14:19:35 -07:00
bpatel 205c078857 search update and adding checks in detect 2019-10-10 12:39:39 -07:00
bpatel 7deba725eb testing 2019-10-09 18:33:56 -07:00
bpatel af0a6cc56b yield results after parsing 2019-10-09 16:50:04 -07:00
bpatel 2046082c82 Merge branch 'run_detections' of https://github.com/splunk/security-content into run_detections 2019-10-09 12:41:43 -07:00
bpatel 28609911dd dashboard update 2019-10-09 12:41:35 -07:00
divious1 c54dccd8e0 updated investigation 2019-10-08 23:43:52 -04:00
bpatel 19becaaa67 yeilding per search name and sample XML 2019-10-08 19:48:08 -07:00
divious1 bbf7728798 Merge branch 'run_detections' of github.com:splunk/security-content into run_detections 2019-10-08 08:37:21 -04:00
divious1 8a7fe2cb8b generating object works now 2019-10-08 08:37:12 -04:00
bpatel d5559b03b5 detect small update 2019-10-07 10:33:51 -07:00
bpatel adba4a2c59 manifest and search updates 2019-10-04 15:15:53 -07:00
bpatel 463ab657a6 adding first and last time the detection resullts fired 2019-10-03 19:28:47 -07:00
bpatel f354a10c34 investigate KV store update: 2019-10-03 11:07:26 -07:00
bpatel 3876690db3 investigate KV store update: 2019-10-03 11:06:15 -07:00
divious1 a07fa1ce88 fixed bug with story parsing and added error condition if no results are returned 2019-10-03 13:40:35 -04:00
bpatel 1cabe30f28 bug fix in run detect function 2019-10-02 17:34:00 -07:00
bpatel 98e018be0a kvstore in investigate 2019-10-02 17:19:58 -07:00
divious1 7d0ddc452c cleaned up some functions 2019-10-02 18:25:55 -04:00
bpatel 5d0904df7a investigation update 2019-10-01 21:40:14 -07:00
bpatel a6add43af8 updating object 2019-10-01 15:11:29 -07:00
divious1 d73299f47e Merge branch 'run_detections' of github.com:splunk/security-content into run_detections 2019-09-26 16:56:27 -07:00
divious1 308e6e57c4 investigate is working just missing parsing results 2019-09-26 16:55:32 -07:00
bpatel 3418ef903f cleaning up 2019-09-26 16:49:06 -07:00
bpatel a1837657de updating entities in manifest 2019-09-26 16:34:12 -07:00
bpatel 834dda11c5 bug fixes 2019-09-26 16:32:29 -07:00
divious1 348ef43cbf fixing a bug with detect 2019-09-26 13:37:58 -07:00
bpatel 7651463417 Merge branch 'run_detections' of https://github.com/splunk/security-content into run_detections 2019-09-26 13:19:07 -07:00
bpatel 83e36dd298 investigate generations 2019-09-26 13:18:09 -07:00
divious1 62b90633b7 moved complex logic into functions 2019-09-26 11:59:05 -07:00
divious1 4d51948eb1 updated detections to a new object type 2019-09-25 17:58:22 -07:00
bpatel ae98b5b6f6 removing two fields from entities 2019-09-19 12:50:37 -07:00
bpatel 7ea62a91ab remoove risk params and use entities 2019-09-19 11:03:25 -07:00
bpatel a3ddc13700 update generate to output entities 2019-09-19 10:44:18 -07:00
bpatel 6bc3283ad4 testing ci with only v2 2019-09-18 18:00:01 -07:00
bpatel efb25dc102 ci code update 2019-09-18 17:49:25 -07:00
bpatel 859f2bd264 updates to gen 2019-09-18 17:15:40 -07:00
bpatel e1310d2192 adding ss.conf spec and example 2019-09-12 16:27:11 -07:00
rvaldez617 6fdc4ff2bf Merge pull request #208 from splunk/CRL-1617_bug
CRL-1617 changed process to process name
2019-09-12 11:15:02 -06:00
bpatel f3cb4bcc2a bumping configparserr 2019-09-12 10:05:57 -07:00
bpatel a04729b663 changed process to process name 2019-09-12 09:55:57 -07:00
rvaldez617 66b5cd25ba Merge pull request #202 from splunk/remove_html_tags
CRL-1611 Remove html tags
2019-09-12 10:41:00 -06:00
Jose Enrique Hernandez b783922e62 Merge pull request #196 from splunk/dependabot/pip/identify-1.4.7
Bump identify from 1.4.6 to 1.4.7
2019-09-12 12:34:58 -04:00