splunk / splunk/contentctl

2x New CICD Checks for Detection Validation

Open
#310 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
139
Forks
52
Avg merge
1h 16m
Merged PRs (30d)
3

Description

1. summaries_only macro missing from tstats search
  • this will help when folks accidentally submit a tstats based detection which directly references summariesonly=t
  • spent far too long to admit troubleshooting why my latest detection didn't trigger, grr.
  • also good for standardisation where this is missing
2. risk object not found in SPL
  • helps ensure the risk objects are relevant
  • may need to look at the last line of SPL, table/ stats or required fields, catches to ensure whole field is compared so src doesn't match on src_ip

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the existing detection validation checks and the CI entry point that runs them. Add coverage for missing summaries_only usage in tstats searches and for risk objects that are absent or not fully compared in the SPL; done means both invalid patterns are reported by validation.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
ci-cd, security, testing-qa
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.