Closed P4T12ICK closed 5 years ago
The following configuration is missing in Olaf Hartong Threat Hunting App under /opt/splunk/etc/apps/ThreatHunting/default/macros.conf:
[indextime] definition = _index_earliest=-15m@m AND _index_latest=now iseval = 0
This macro is used in every Hunting search, that's why the searches were not working.
Does detection lab also need the Lookup File Editor App @olafhartong? I believe this app is missing currently from Detection Lab and is a prerequisite.
Both should be fixed in #299
The following configuration is missing in Olaf Hartong Threat Hunting App under /opt/splunk/etc/apps/ThreatHunting/default/macros.conf:
[indextime] definition = _index_earliest=-15m@m AND _index_latest=now iseval = 0
This macro is used in every Hunting search, that's why the searches were not working.