splunk / splunk/contentctl

Expand risk message validation to ensure appropriate field values are present

Open
#346 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
139
Forks
52
Avg merge
1h 16m
Merged PRs (30d)
3

Description

  • During risk message validation, we ensure that none of the field tokens remain unreplaced in the risk event message
  • We could take this an additional step by determining the expected field values from the raw event, and ensuring they all DO appear in the risk message as well

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the existing risk message validation entry point and trace how raw events and field tokens are handled. Determine the expected field values from the raw event and verify that each appears in the risk message, while preserving the existing unreplaced-token check. Done means validation rejects messages missing expected values and accepts complete messages.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.