Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(adaptiveResponse): add verbose details for AR alert action (#1135)
- Contains changes for adaptive response that can be created from the `globalConfig` - Added the supported parameters by AR framework - Updated test cases to reflect the changes - Handled migration of users using `activeResponse` and change it to `adaptiveResponse` - Provided a warning log if any users are using `activeResponse`
- Loading branch information
1 parent
2b269cc
commit b19d678
Showing
29 changed files
with
69 additions
and
53 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
4 changes: 2 additions & 2 deletions
4
...add_on_ucc_framework/commands/modular_alert_builder/arf_template/eventtypes.conf.template
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,7 +1,7 @@ | ||
{% for alert in mod_alerts %} | ||
{% if alert.get("active_response") and alert.active_response.get("sourcetype") %} | ||
{% if alert.get("adaptive_response") and alert.adaptive_response.get("sourcetype") %} | ||
[{{ alert.short_name }}_modaction_result] | ||
search = {{ 'sourcetype="' + alert.active_response.sourcetype + '"' }} | ||
search = {{ 'sourcetype="' + alert.adaptive_response.sourcetype + '"' }} | ||
{% endif %} | ||
{% endfor %} | ||
|
2 changes: 1 addition & 1 deletion
2
splunk_add_on_ucc_framework/commands/modular_alert_builder/arf_template/tags.conf.template
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
2 changes: 1 addition & 1 deletion
2
..._global_config_configuration/Splunk_TA_UCCExample/appserver/static/js/build/entry_page.js
Large diffs are not rendered by default.
Oops, something went wrong.
2 changes: 1 addition & 1 deletion
2
...ected_output_global_config_everything/Splunk_TA_UCCExample/README/alert_actions.conf.spec
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
2 changes: 1 addition & 1 deletion
2
...put_global_config_everything/Splunk_TA_UCCExample/appserver/static/js/build/entry_page.js
Large diffs are not rendered by default.
Oops, something went wrong.
2 changes: 1 addition & 1 deletion
2
.../expected_output_global_config_everything/Splunk_TA_UCCExample/default/alert_actions.conf
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
5 changes: 2 additions & 3 deletions
5
...ons/expected_output_global_config_everything/Splunk_TA_UCCExample/default/eventtypes.conf
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1,3 @@ | ||
[test_alert_modaction_result] | ||
search = sourcetype="test:incident" | ||
|
||
# Just something | ||
[UCC_NOT_GENERATED] | ||
search = index=_internal sourcetype=splunkd |
5 changes: 2 additions & 3 deletions
5
...ed_addons/expected_output_global_config_everything/Splunk_TA_UCCExample/default/tags.conf
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1,3 @@ | ||
|
||
[eventtype=UCC_NOT_GENERATED] | ||
notalert = enabled | ||
[eventtype=test_alert_modaction_result] | ||
modaction_result = enabled | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
4 changes: 0 additions & 4 deletions
4
tests/testdata/test_addons/package_global_config_everything/package/default/eventtypes.conf
This file was deleted.
Oops, something went wrong.
4 changes: 0 additions & 4 deletions
4
tests/testdata/test_addons/package_global_config_everything/package/default/tags.conf
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
4 changes: 0 additions & 4 deletions
4
...ta/test_addons/package_global_config_everything_uccignore/package/default/eventtypes.conf
This file was deleted.
Oops, something went wrong.
4 changes: 0 additions & 4 deletions
4
...testdata/test_addons/package_global_config_everything_uccignore/package/default/tags.conf
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters