splunk / contentctl

Splunk Content Control Tool
Apache License 2.0
80 stars 20 forks source link

SA Admon lookup exclusion #210

Closed patel-bhavin closed 1 month ago

patel-bhavin commented 1 month ago

This PR is failing on contentctl build for https://github.com/splunk/security_content/pull/3026 , since there is a detection which this lookup admon_groups_def which not present in the ESCU app.

The lookup is shipped by another app called : SA-admon. Hence adding it to this exclusion list!