v0.5.2 - Splunk CIM CSV export
Sixth release of mispSK.
Added
export_splunk.py: export one or more MISP events' attributes to a Splunk CIM-oriented CSV filemispsk/splunk.py:classify_cim_datamodel,split_composite_value,map_attribute_to_cim_fields,build_csv_row,build_splunk_export- CIM field mapping across six Splunk data models:
Network_Traffic,Web,Malware,Endpoint,Email,Certificates - One CSV row per attribute, with
raw_valueas a generic fallback andcim_datamodelindicating the matched model - Composite types (
ip-src|port,filename|md5,regkey|value, etc.) automatically split across their two CIM columns --id/--idsfor single or batch event export--include-non-idsflag - onlyto_ids=Trueattributes are exported by defaulttests/test_splunk.py
Known limitation
- CIM mapping covers the types most relevant to SOC/CTI analysis; unmapped types are still exported via
raw_value - This is a lightweight standalone CSV export, not a replacement for Splunk's Threat Intelligence Framework or the misp42splunk app
See CHANGELOG.md for full details and ROADMAP.md.