View Code? Open in Web Editor
NEW
This TA can be used to fill in detection gaps following a period of data collection interruption. Once data are recovered in Splunk, this application can be used to restart scheduled searches during this outage.
License: MIT License
Python 99.81%
Ruby 0.01%
HTML 0.19%
ta-detection-backfill's People
Contributors
Stargazers
Watchers
ta-detection-backfill's Issues
Request Type
Bug
Problem Description
if os .path .exists (self .backlog_file ):
with open (self .backlog_file , 'r' ) as file :
content = csv .reader (file )
header = next (content )
Causing an issue if the file is existing but empty (no headers)
Request Type
Bug
Problem Description
if m and self .original_pattern != "now" :
# Extract the information
self .snap = m .group ('snap' )
self .snapOff = m .group ('snapOff' )
self .snapUnit = m .group ('snapUnit' )
self .offset1 = m .group ('offset1' )
self .unit1 = m .group ('unit1' )
self .offset2 = m .group ('offset2' )
self .unit2 = m .group ('unit2' )
process_pattern isn't designed to managed "now" times, need to work on this