Files
splunk-security_content/deployments/deployment_example_1.yml
2020-05-06 17:42:38 +02:00

21 lines
513 B
YAML

name: Enterprise Security deployment configuration
id: bc91a8cd-35e7-4bb2-6140-e756cc46f212
date: '2020-04-27'
description: This configuration file applies to all correlation searches that are used for detection
author: Bhavin Patel
scheduling:
cron_schedule: '*/30 * * * *'
earliest_time: -30m
latest_time: now
schedule_window: auto
alert_action:
notable:
rule_description: '%description%'
rule_title: '%name%'
nes_fields:
- user
- dest
- src
tags:
analytics_story: all