Skip to content

Comments

Fixes for 5.0.0a2#351

Merged
patel-bhavin merged 13 commits intomainfrom
tags_observable_removal
Jan 23, 2025
Merged

Fixes for 5.0.0a2#351
patel-bhavin merged 13 commits intomainfrom
tags_observable_removal

Conversation

@ljstella
Copy link
Contributor

@ljstella ljstella commented Jan 22, 2025

What's included?

  • Last vestiges of detection.tag.observable in testing
  • Field Aliases fix in Risk_Event.py from @cmcginley-splunk
  • Migrated not-currently-in-use drilldown code to use detection.rba instead of detection.tags.observable
  • Removed commented out code using observables
  • removing code referencing observables #352
  • transforms.conf formatting for match_type
  • hunting searches not having a Risk config caused issues with testing them
  • .mlmodel files renamed in err

@ljstella
Copy link
Contributor Author

Last commit that removed Observables from the DetectionTags model caught these two stragglers: splunk/security_content#3289

ljstella and others added 8 commits January 22, 2025 14:06
hunting searches, which by definition
do NOT have rba sections (more specifically,
detections.rba is None).
drilldown search generation code
more actually defined for it
filename and app_filename
fields work to fix MlModel
lookup support. These lookups
now no longer exist in
transforms.conf or
have datetime stamps
at the end of the mlmodel
files when written to the app.
This differs from how they
were treated previously and
how CSV files are treated.
getElapsedTime included in
error. clean up imports.
@ljstella ljstella requested a review from patel-bhavin January 23, 2025 21:51
@patel-bhavin patel-bhavin merged commit a56beeb into main Jan 23, 2025
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants