Conversation
Contributor
Author
|
Last commit that removed Observables from the DetectionTags model caught these two stragglers: splunk/security_content#3289 |
hunting searches, which by definition do NOT have rba sections (more specifically, detections.rba is None).
drilldown search generation code
removing code referencing observables
more actually defined for it
filename and app_filename fields work to fix MlModel lookup support. These lookups now no longer exist in transforms.conf or have datetime stamps at the end of the mlmodel files when written to the app. This differs from how they were treated previously and how CSV files are treated.
getElapsedTime included in error. clean up imports.
patel-bhavin
approved these changes
Jan 23, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What's included?
match_type