mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
21 lines
513 B
YAML
21 lines
513 B
YAML
name: Enterprise Security deployment configuration
|
|
id: bc91a8cd-35e7-4bb2-6140-e756cc46f212
|
|
date: '2020-04-27'
|
|
description: This configuration file applies to all correlation searches that are used for detection
|
|
author: Bhavin Patel
|
|
scheduling:
|
|
cron_schedule: '*/30 * * * *'
|
|
earliest_time: -30m
|
|
latest_time: now
|
|
schedule_window: auto
|
|
alert_action:
|
|
notable:
|
|
rule_description: '%description%'
|
|
rule_title: '%name%'
|
|
nes_fields:
|
|
- user
|
|
- dest
|
|
- src
|
|
tags:
|
|
analytics_story: all
|