clong / clong/DetectionLab

ESXi - Splunk Threat Hunting App issue

Open
#733 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
HTML
Stars
5k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

Hi again,

I managed to deploy the lab on a ESXi 7.0.3 host running on Intel NUC 11.

The only issue I have now is related to Splunk Threat Hunting App which shows zero threats all the time. I tried executing all Atomic Red Bomb tests and there are no changes after that.

The Threat Hunting App complains about missing threathunting_asset_priority.csv. I created this file similar to the instructions posted here: https://github.com/clong/DetectionLab/issues/706 however no significant changes. I also unarchived the whitelist csv files from Olaf.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.