olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.12k stars 177 forks source link

fixes for the savedsearches #23

Closed aholzel closed 1 year ago

aholzel commented 5 years ago
olafhartong commented 5 years ago

Thanks for the pull request! Appreciate you taking the time to contribute Wouldn't the already added schedule_window = auto also address this ?

aholzel commented 5 years ago

No problem! Unfortunately not enough, for what I have seen. I had an installation that had a lot of skipped searches on exactly every 15 minutes. When I spread out the searches there where no more skipped searches. This is probably because on an Splunk ES seachhead there are a lot of searches on a */5 Cron schedule.

Cris5955 commented 2 years ago

Forma de resolverlo con ..

dstaulcu commented 1 year ago

was just looking at outstanding pull requests. Have yall seen the allow_skew feature in savedsearches.conf? I don't know what version of Splunk allow_skew was introduced with but seems like that would be a nice option over having to hard code offsets among scheduled searches. that said, looks like those offsets were merged outside of this pull request at some point so it also seems this pull request could be closed.