splunk / splunk/contentctl

Ability to Build a Set of Detections Filtered by Tag

Open
#182 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
139
Forks
52
Avg merge
1h 16m
Merged PRs (30d)
3

Description

This may exist already and I'm just not seeing it but for my use case I would love to be able to build a subset of detection content based on a tag set in a yaml file passed into the cli. (i.e. contentctl build --tag something)

For example, an MSSP could tag content to which customers have data that support it and then build a custom detection app with just their content. Or if you wanted to build an app that just supported a specific use case you could pass in that tag etc.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the contentctl build CLI entry point and inspect how detection content and tags are currently selected. Determine whether tag filtering already exists, then define the supported YAML or --tag input and verify that a build contains only content matching the requested tag set.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cli
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.