mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
6c4516730d
update_timestamp and modified testing code to always update timestamp. This will cause some issues as not all sourcetypes are supported, yet. We will work to support them all before merging these changes to develop.
17 lines
730 B
YAML
17 lines
730 B
YAML
name: Windows Event Log Cleared Unit Test
|
|
tests:
|
|
- name: Windows Event Log Cleared
|
|
file: endpoint/windows_event_log_cleared.yml
|
|
pass_condition: '| stats count | where count > 0'
|
|
earliest_time: -24h
|
|
latest_time: now
|
|
attack_data:
|
|
- file_name: windows-security.log
|
|
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-security.log
|
|
source: WinEventLog:Security
|
|
sourcetype: WinEventLog
|
|
- file_name: windows-system.log
|
|
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/atomic_red_team/windows-system.log
|
|
source: WinEventLog:System
|
|
sourcetype: WinEventLog
|