Skip to content

v0.5.2 - Splunk CIM CSV export

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 06 Aug 20:17
· 14 commits to main since this release

Sixth release of mispSK.

Added

  • export_splunk.py: export one or more MISP events' attributes to a Splunk CIM-oriented CSV file
  • mispsk/splunk.py: classify_cim_datamodel, split_composite_value, map_attribute_to_cim_fields, build_csv_row, build_splunk_export
  • CIM field mapping across six Splunk data models: Network_Traffic, Web, Malware, Endpoint, Email, Certificates
  • One CSV row per attribute, with raw_value as a generic fallback and cim_datamodel indicating the matched model
  • Composite types (ip-src|port, filename|md5, regkey|value, etc.) automatically split across their two CIM columns
  • --id / --ids for single or batch event export
  • --include-non-ids flag - only to_ids=True attributes are exported by default
  • tests/test_splunk.py

Known limitation

  • CIM mapping covers the types most relevant to SOC/CTI analysis; unmapped types are still exported via raw_value
  • This is a lightweight standalone CSV export, not a replacement for Splunk's Threat Intelligence Framework or the misp42splunk app

See CHANGELOG.md for full details and ROADMAP.md.