splunk / splunk/contentctl

Email action support

Open
#272 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
139
Forks
52
Avg merge
1h 16m
Merged PRs (30d)
3

Description

I'd raise a PR to flesh out the current partial implementation if I could figure out how to do it...

We use email actions on a handful of detections to initiate callouts (don't ask, I'm not a fan but it's the norm in my org) and it would be awesome if we were able to configure these in our content pack.

Field support for our use case doesn't need to be extensive, just the to, subject and message fields are sufficient, though it would be a bonus if some of the attachment, inline results, or results link options were available.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the current partial email-action implementation and how content-pack action fields are represented. Confirm how the to, subject, and message values flow through configuration, then add coverage showing those fields can be configured; attachment, inline-result, and results-link support is optional.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
tooling
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.