Closed tcwaddell closed 6 years ago
Malzoo uses a hardcoded sourcetype in the Splunk tool. It would be easier to integrate Malzoo with Splunk if this could be specified in the configuration file.
https://github.com/nheijmans/malzoo/blob/a598dabcc36e44f3ec0ab6a4b16924ac7be17c7d/malzoo/core/tools/splunk.py#L14-L19
3acd21d contains the update suggestion!
Malzoo uses a hardcoded sourcetype in the Splunk tool. It would be easier to integrate Malzoo with Splunk if this could be specified in the configuration file.
https://github.com/nheijmans/malzoo/blob/a598dabcc36e44f3ec0ab6a4b16924ac7be17c7d/malzoo/core/tools/splunk.py#L14-L19