issues
search
splunk
/
contentctl
Splunk Content Control Tool
Apache License 2.0
91
stars
25
forks
source link
2x New CICD Checks for Detection Validation
#310
Open
dluxtron
opened
1 month ago
dluxtron
commented
1 month ago
1. summaries_only macro missing from tstats search
this will help when folks accidentally submit a tstats based detection which directly references summariesonly=t
spent far too long to admit troubleshooting why my latest detection didn't trigger, grr.
also good for standardisation where this is missing
2. risk object not found in SPL
helps ensure the risk objects are relevant
may need to look at the last line of SPL, table/ stats or required fields, catches to ensure whole field is compared so src doesn't match on src_ip
1. summaries_only macro missing from tstats search
2. risk object not found in SPL