Skip to content

Conversation

@pyth0n1c
Copy link
Collaborator

@pyth0n1c pyth0n1c commented Aug 3, 2022

Merging in the changes made for the Detection as Code talk by Patrick and Eric at .conf22. These changes allow a user to remove all the Splunk content from security_content so that a user can add their own. They also make it possible to build, validate, and deploy and app to a Splunk Cloud instance using ACS using just the contentctl tool!

pyth0n1c added 26 commits April 22, 2022 11:59
… errorneous comma from lookups/attack_tools.csv that caused errors during appinspect and resulted in a badly cormatted csv.
Updated command line arguments
for build.  Improved implmentation of
inspect.
a default argument for deploy.
…for distributing the tool standalone in a separate repo as opposed to a part of the security_content repo.
… Successfully built, then manually deployed an app to a Splunk Cloud instance using the ACS command line. The next steps will be to integrate the command line functionality into this app via the deploy option.
…ment of apps to Splunk Cloud using Automated Private App Vetting / APAV
…ether the acs command has failed since even an ACS failure gives a return code of 0. I have raised this issue with the ACS team and am waiting on a reponse and guidance.
enums, and initialize to support
building the app scaffold and
removing all the content that needs
to be removed.
documentation in contentctl help.
@auto-assign auto-assign bot requested a review from rosplk August 3, 2022 15:10
patel-bhavin
patel-bhavin previously approved these changes Aug 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants