Files
splunk-security_content/deployments/deployment_example_2.yml
T
2020-05-06 17:42:38 +02:00

18 lines
500 B
YAML

name: Enterprise Security deployment configuration
id: bc91a8cd-35e7-4bb2-6140-e756cc46f212
date: '2020-04-27'
description: This configuration file applies to all correlation searches that are used for detection
author: Bhavin Patel
scheduling:
cron_schedule: '*/60 * * * *'
earliest_time: -60m
latest_time: now
schedule_window: auto
alert_action:
email:
to: 'test@test.de'
subject: 'Splunk Alert: $name$'
message: 'Splunk Alert $name$ triggered'
tags:
mitre_attack_id: T1003