Files
splunk-security_content/lookups/cloud_instances_enough_data.yml
2025-03-26 11:01:05 -05:00

14 lines
375 B
YAML

name: cloud_instances_enough_data
date: 2024-12-23
version: 2
id: 2aabac97-9782-4156-9dfd-7c1fb7aab2a6
author: Splunk Threat Research Team
lookup_type: kvstore
description: A lookup to determine if you have a sufficient amount of time has passed to collect cloud instance data for behavioral searches
fields:
- _key
- filter
- enough_data
match_type:
- WILDCARD(filter)