Skip to content

Commit

Permalink
Updating Github with Content from ESCU - v4.31.0
Browse files Browse the repository at this point in the history
  • Loading branch information
research bot committed May 8, 2024
1 parent d18df04 commit c3d39a3
Show file tree
Hide file tree
Showing 84 changed files with 18,019 additions and 15,984 deletions.
4 changes: 2 additions & 2 deletions contentctl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,11 @@ app:
uid: 3449
title: ES Content Updates
appid: DA-ESS-ContentUpdate
version: 4.30.0
version: 4.31.0
description: Explore the Analytic Stories included with ES Content Updates.
prefix: ESCU
build: 004210
version: 4.30.0
version: 4.31.0
label: ES Content Updates
author_name: Splunk Threat Research Team
author_email: research@splunk.com
Expand Down
2 changes: 1 addition & 1 deletion dist/DA-ESS-ContentUpdate/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,4 @@ This subscription service delivers pre-packaged Security Content for use with Sp

Requires Splunk Enterprise Security version 4.5 or greater.

For more information please visit the [Splunk ES Content Update user documentation](https://docs.splunk.com/Documentation/ESSOC).
For more information please visit the [Splunk ES Content Update user documentation](https://docs.splunk.com/Documentation/ESSOC).
6 changes: 3 additions & 3 deletions dist/DA-ESS-ContentUpdate/app.manifest
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
{
"schemaVersion": "1.0.0",
"info": {
"title": "DA-ESS-ContentUpdate",
"title": "ES Content Updates",
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "4.30.0"
"version": "4.31.0"
},
"author": [
{
Expand All @@ -14,7 +14,7 @@
"company": "Splunk"
}
],
"releaseDate": null,
"releaseDate": "2024-05-08",
"description": "Explore the Analytic Stories included with ES Content Updates.",
"classification": {
"intendedAudience": null,
Expand Down
7,103 changes: 3,558 additions & 3,545 deletions dist/DA-ESS-ContentUpdate/default/analyticstories.conf

Large diffs are not rendered by default.

11 changes: 6 additions & 5 deletions dist/DA-ESS-ContentUpdate/default/app.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2024-04-17T22:08:10 UTC
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:53 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
Expand All @@ -10,7 +11,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 20240417220604
build = 20240508171020

[triggers]
reload.analytic_stories = simple
Expand All @@ -26,12 +27,12 @@ reload.es_investigations = simple

[launcher]
author = Splunk
version = 4.30.0
version = 4.31.0
description = Explore the Analytic Stories included with ES Content Updates.

[ui]
is_visible = true
label = DA-ESS-ContentUpdate
label = ES Content Updates

[package]
id = DA-ESS-ContentUpdate
Expand Down
13 changes: 7 additions & 6 deletions dist/DA-ESS-ContentUpdate/default/collections.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2024-04-17T22:08:10 UTC
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:53 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
Expand Down Expand Up @@ -29,10 +30,6 @@ replicate = false
enforceTypes = false
replicate = false

[previously_seen_S3_access_from_remote_ip]
enforceTypes = false
replicate = false

[previously_seen_api_calls_from_user_roles]
enforceTypes = false
replicate = false
Expand Down Expand Up @@ -81,6 +78,10 @@ replicate = false
enforceTypes = false
replicate = false

[previously_seen_S3_access_from_remote_ip]
enforceTypes = false
replicate = false

[previously_seen_users_console_logins]
enforceTypes = false
replicate = false
Expand Down
7 changes: 4 additions & 3 deletions dist/DA-ESS-ContentUpdate/default/content-version.conf
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2024-04-17T22:08:10 UTC
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:53 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
[content-version]
version = 4.30.0
version = 4.31.0
1 change: 1 addition & 0 deletions dist/DA-ESS-ContentUpdate/default/data/ui/nav/default.xml
Original file line number Diff line number Diff line change
Expand Up @@ -2,5 +2,6 @@
<view name="escu_summary" default="true"/>
<view name="feedback"/>
<view name="search"/>
<view name="dashboards"/>
<a href="http://docs.splunk.com/Documentation/ESSOC">Docs</a>
</nav>
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,12 @@
<!--
#############
# Automatically generated by 'contentctl build' from
# https://github.com/splunk/contentctl
# On Date: 2024-05-08T17:10:54 UTC
# Author: Splunk Threat Research Team - Splunk
# Contact: research@splunk.com
#############
-->
<panel>
<table>
<search>
Expand Down

0 comments on commit c3d39a3

Please sign in to comment.