DCSO / TIE-Splunk-TA

DCSO Threat Intelligence Engine (TIE) Add-On for Splunk v8
BSD 3-Clause "New" or "Revised" License
3 stars 2 forks source link

[Feat] IoC Column Fields Selectable #5

Open 8ear opened 5 years ago

8ear commented 5 years ago

Why

Not every company wants the same data in its Splunk system, so different TIE columns may not be needed in the system. However, each column field costs Splunk index volume, download and processing time.

What

Every available column field should be selectable via the web interface and only the activated column fields should be used. The default should be selected and the rest should be available via advanced setting button.

The following JSON elements are available in the TIE and should be usable:

Default activated:

A great example can be:

How