Files
splunk-security_content/deployments/00_default_hunting.yml
2022-12-01 14:34:23 +01:00

13 lines
336 B
YAML

name: ESCU Default Configuration Hunting
id: cc5895e8-3420-4ab7-af38-cf87a28f9c3b
date: '2021-12-21'
author: Patrick Bareiss
description: This configuration file applies to all detections of type hunting.
scheduling:
cron_schedule: 0 * * * *
earliest_time: -70m@m
latest_time: -10m@m
schedule_window: auto
tags:
type: Hunting