Skip to content

Commit

Permalink
Merge pull request #3107 from splunk/aws_asl_detection_fix
Browse files Browse the repository at this point in the history
Improvements AWS ASL detection
  • Loading branch information
patel-bhavin committed Sep 4, 2024
2 parents d4e100a + 6bf0641 commit af0ebae
Show file tree
Hide file tree
Showing 53 changed files with 60 additions and 60 deletions.
2 changes: 1 addition & 1 deletion data_sources/aws_cloudfront.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ sourcetype: aws:cloudfront:accesslogs
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,5 +10,5 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0

2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_assumerolewithsaml.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_consolelogin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_copyobject.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createaccesskey.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createkey.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createloginprofile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createnetworkaclentry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createpolicyversion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createsnapshot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createtask.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createvirtualmfadevice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deactivatemfadevice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletealarms.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletedetector.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletegroup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleteipset.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleteloggroup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletelogstream.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletenetworkaclentry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletepolicy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleterule.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletesnapshot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletetrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletewebacl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_describeeventaggregates.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_describeimagescanfindings.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_getobject.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_getpassworddata.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_jobcreated.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_modifydbinstance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_modifyimageattribute.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_modifysnapshotattribute.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_putbucketacl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_putbucketlifecycle.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_putbucketreplication.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_putbucketversioning.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_putimage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_putkeypolicy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_replacenetworkaclentry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.6.0
version: 7.7.0
fields:
- _time
- action
Expand Down
Loading

0 comments on commit af0ebae

Please sign in to comment.