Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions contentctl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -143,9 +143,9 @@ apps:
- uid: 1876
title: Splunk Add-on for AWS
appid: Splunk_TA_aws
version: 7.10.0
version: 7.11.0
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_7100.tgz
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_7110.tgz
- uid: 3088
title: Splunk Add-on for Google Cloud Platform
appid: SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM
Expand Down
2 changes: 1 addition & 1 deletion data_sources/asl_aws_cloudtrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ separator: api.operation
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
output_fields:
- dest
- user
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudfront.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ sourcetype: aws:cloudfront:accesslogs
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,4 +10,4 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_assumerolewithsaml.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ separator_value: AssumeRoleWithSAML
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_consolelogin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ separator_value: ConsoleLogin
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_copyobject.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CopyObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createaccesskey.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateAccessKey
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createkey.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateKey
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createloginprofile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateLoginProfile
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createnetworkaclentry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createpolicyversion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreatePolicyVersion
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createsnapshot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateSnapshot
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createtask.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateTask
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_createvirtualmfadevice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: CreateVirtualMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deactivatemfadevice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeactivateMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: DeleteAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletealarms.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteAlarms
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletedetector.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteDetector
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletegroup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteGroup
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleteguardrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ separator_value: DeleteGuardrail
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleteipset.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ separator_value: DeleteIPSet
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleteknowledgebase.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ separator_value: DeleteKnowledgeBase
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
example_log: ''
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleteloggroup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteLogGroup
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletelogstream.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteLogStream
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- apiVersion
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ separator_value: DeleteModelInvocationLoggingConfiguration
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletenetworkaclentry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ separator_value: DeleteNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletepolicy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: DeletePolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleterule.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteRule
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deleterulegroup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
example_log: ''
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletesnapshot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteSnapshot
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletetrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ separator_value: DeleteTrail
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletevirtualmfadevice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: DeleteVirtualMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_deletewebacl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: DeleteWebACL
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- apiVersion
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_describeeventaggregates.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: DescribeEventAggregates
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ separator_value: DescribeImageScanFindings
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- action
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: GetAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_getobject.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ separator_value: GetObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- additionalEventData.AuthenticationMethod
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_getpassworddata.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ separator_value: GetPasswordData
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_invokemodel.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ separator_value: InvokeModel
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_jobcreated.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ separator_value: JobCreated
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- app
Expand Down
2 changes: 1 addition & 1 deletion data_sources/aws_cloudtrail_listfoundationmodels.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ separator_value: ListFoundationModels
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.10.0
version: 7.11.0
fields:
- _time
- action
Expand Down
Loading
Loading