Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New version of the Splunk analyzer for Cortex #534

Merged
merged 12 commits into from
Aug 10, 2020

Conversation

LetMeR00t
Copy link
Contributor

Hello everyone,

This is a new analyzer for Cortex which is able to search data into Splunk.
This version is different (even if inspired) from this PR : #142

For those who known how Splunk work, I though that this PR was not a good version of how a Splunk analyzer must be. In this new version, we are using savedsearches. No request is hardcoded in the JSON files. Moreover, templates are now available for TheHive.

Please, let me know if I have to change something but this analyzer seems to be a must have for me.

I will update the CortexDocs soon to have all the details about this analyzer of course.

Thank you

@LetMeR00t
Copy link
Contributor Author

LetMeR00t commented Sep 19, 2019

Documentation is done and a PR is waiting.

Here some screenshots of the result :
image
image
image
Note: Here saved searches are called "Temporary"

Thank you

@LetMeR00t
Copy link
Contributor Author

Hi,
upstream/master (your master) was merged into this feature
Thank you

@DaveCLowe
Copy link

What needs to happen to merge this PR? It would be very helpful.
Thanks

@LetMeR00t
Copy link
Contributor Author

Hi,
upstream/master (your master) was merged into this feature
Thank you

@jeromeleonard jeromeleonard changed the base branch from master to develop August 6, 2020 14:50
@jeromeleonard jeromeleonard mentioned this pull request Aug 10, 2020
@jeromeleonard jeromeleonard merged commit bcf4d15 into TheHive-Project:develop Aug 10, 2020
@LetMeR00t
Copy link
Contributor Author

Thank you.
If you need any help according to this analyzer, please mention me.

@jeromeleonard
Copy link
Contributor

jeromeleonard commented Aug 10, 2020

Thank you. Yes we might indeed need some help. We used to use CortexDocs for documentation. In the meantime, we migrated our documentation to https://thehive-project.github.io/Cortex-Analyzers. Do you think it is possible to update this analyzer to contain all interesting info for the documentation ? All instructions there: https://thehive-project.github.io/Cortex-Analyzers/analyzers_definition/

@LetMeR00t
Copy link
Contributor Author

@jeromeleonard ,
No problem at all, I will handle it.
Just one question, do you have a specific branch for this new documentation ? I can't find any example of the Markdown file used in your documentation on your repository ... of course to use the same structure.
Thank you :)

@jeromeleonard
Copy link
Contributor

Everything is automatically generated based on JSON content and README.md file. An example can be found for The Domaintools_Iris analyzer.

@LetMeR00t
Copy link
Contributor Author

Hi @jeromeleonard,
As requested, you will find the documentation in this new PR : #837
I wasn't able to test it so if you have any trouble, please let me know.
Thank you

@jeromeleonard
Copy link
Contributor

thank you very much. merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants