mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
14 lines
375 B
YAML
14 lines
375 B
YAML
name: cloud_instances_enough_data
|
|
date: 2024-12-23
|
|
version: 2
|
|
id: 2aabac97-9782-4156-9dfd-7c1fb7aab2a6
|
|
author: Splunk Threat Research Team
|
|
lookup_type: kvstore
|
|
description: A lookup to determine if you have a sufficient amount of time has passed to collect cloud instance data for behavioral searches
|
|
fields:
|
|
- _key
|
|
- filter
|
|
- enough_data
|
|
match_type:
|
|
- WILDCARD(filter)
|