Comments (5)
This issue is fixed in 3.10.0. Thank you @knadkarni-splunk for creating this and giving details
from security_content.
@knadkarni-splunk : those work bench searches are intended to work with single artifacts only. There is no easy way currently to customize those with our current tooling.
from security_content.
@patel-bhavin Can't the panels be designed to take multiple values for tokens into account (Using delimiters ,value prefix and value suffix)? Can this be addressed in an upcoming release?
from security_content.
@knadkarni-splunk : After doing a bunch of testing/tweaks with our current script that generates es_investigations.conf
, it seems like we might be able to handle multiple values.
That said, it looks like a size-able amount of work as we'd have to update all the searches in the response tasks directory. Will keep you posted on when this will be ready
from security_content.
tracking this in https://github.com/splunk/security-content/pull/new/workbench_issue_697 -> no longer a correct branch
New branch: #987
from security_content.
Related Issues (20)
- kubernetes detections to be ported to opentelemetry output because of EOS of sc4k HOT 1
- [BUG] Azure AD Authentication Failed During MFA Challenge - Rename userPrincipalName field HOT 1
- [BUG] Unable to overwrite default lookup with custom lookup in macro dynamic_dns_providers HOT 1
- Improve performance of pretrained DGA model HOT 2
- [BUG] Splunk Attack Analyzer Input Playbok HOT 1
- [BUG] Broken link and missing instructions for producing MITRE Navigator map HOT 1
- [Feature Req] MITRE ATT&CK IDs are not versioned in published content HOT 1
- Hi All, I am facing an issue when trying to configure the attack range locally.... The error I am getting is 'configuration.py, line 150, answers = questionary.prompt(questions) NameError: name 'questionary' is not defined. Did you mean: 'questions''... I cant find any answers online from people having the same issue.[BUG] HOT 1
- When trying to build attack range I get the following error 'No module named 'azure.mgmt.resource'[BUG] HOT 1
- Build constraints based on tags HOT 1
- [BUG] Active_Directory_Disable_Account_Dispatch HOT 1
- [BUG] VirusTotal v3 Identifier Reputation Playbook failing with math domain error HOT 2
- [BUG] False positive in rule "Suspicious Copy on System32" HOT 2
- [BUG] `Unusually Long Command Line` Detection has incorrect Risk Message and Threat Object HOT 1
- [BUG] artifact_update custom function fails if cef_value passed is 0
- [BUG] Windows Excessive Disabled Services Event uses ComputerName instead of src field (CIM issue) HOT 3
- [BUG] ESCU CS fields LogonType and TargetUserName HOT 3
- [BUG] System Processes Run From Unexpected Locations - missing field for Risk Message HOT 2
- [BUG] HOT 1
- [BUG] - Build Failing Everytime HOT 4
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from security_content.