Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

auditd_sourcetype_update #3136

Open
wants to merge 69 commits into
base: develop
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
69 commits
Select commit Hold shift + click to select a range
bc09282
auditd_sourcetype_update
tccontre Sep 24, 2024
7cbc846
Branch was auto-updated.
patel-bhavin Sep 24, 2024
3b3c0da
auditd_sourcetype_update
tccontre Sep 25, 2024
14b4b9f
Branch was auto-updated.
patel-bhavin Sep 25, 2024
600634d
Branch was auto-updated.
patel-bhavin Sep 25, 2024
d4133da
Branch was auto-updated.
patel-bhavin Oct 3, 2024
83cf299
Branch was auto-updated.
patel-bhavin Oct 9, 2024
3bb12f9
Branch was auto-updated.
patel-bhavin Oct 9, 2024
a558159
Branch was auto-updated.
patel-bhavin Oct 10, 2024
e224b57
Branch was auto-updated.
patel-bhavin Oct 10, 2024
ab7c689
Branch was auto-updated.
patel-bhavin Oct 10, 2024
d8e80df
Branch was auto-updated.
patel-bhavin Oct 15, 2024
1466895
Branch was auto-updated.
patel-bhavin Oct 15, 2024
354610a
Branch was auto-updated.
patel-bhavin Oct 15, 2024
42eb1a5
Branch was auto-updated.
patel-bhavin Oct 16, 2024
96841dd
Branch was auto-updated.
patel-bhavin Oct 16, 2024
319ed10
Branch was auto-updated.
patel-bhavin Oct 16, 2024
a23b538
Branch was auto-updated.
patel-bhavin Oct 17, 2024
312a145
Branch was auto-updated.
patel-bhavin Oct 22, 2024
8a1e99c
Branch was auto-updated.
patel-bhavin Oct 22, 2024
5b03faf
Branch was auto-updated.
patel-bhavin Oct 23, 2024
21efb02
Branch was auto-updated.
patel-bhavin Oct 23, 2024
851d065
Branch was auto-updated.
patel-bhavin Oct 24, 2024
92a9f3b
Branch was auto-updated.
patel-bhavin Oct 28, 2024
06f5969
Branch was auto-updated.
patel-bhavin Oct 29, 2024
dcf0a3b
Branch was auto-updated.
patel-bhavin Oct 29, 2024
4b7c0c3
Branch was auto-updated.
patel-bhavin Oct 31, 2024
d2965ee
Branch was auto-updated.
patel-bhavin Oct 31, 2024
c1f5bdf
Branch was auto-updated.
patel-bhavin Oct 31, 2024
b7fa8ec
Branch was auto-updated.
patel-bhavin Oct 31, 2024
d936b3c
Branch was auto-updated.
patel-bhavin Nov 1, 2024
b0ffdba
Branch was auto-updated.
patel-bhavin Nov 1, 2024
500f5d8
Branch was auto-updated.
patel-bhavin Nov 1, 2024
373fc09
Branch was auto-updated.
patel-bhavin Nov 1, 2024
0a9bb4d
Branch was auto-updated.
patel-bhavin Nov 4, 2024
c05ecb8
Branch was auto-updated.
patel-bhavin Nov 6, 2024
e06b2da
Branch was auto-updated.
patel-bhavin Nov 6, 2024
cf99fac
Branch was auto-updated.
patel-bhavin Nov 6, 2024
eca59f0
Branch was auto-updated.
patel-bhavin Nov 6, 2024
b9c6533
Branch was auto-updated.
patel-bhavin Nov 6, 2024
55645ae
Branch was auto-updated.
patel-bhavin Nov 6, 2024
c6bf257
Branch was auto-updated.
patel-bhavin Nov 7, 2024
1b1c7d9
Branch was auto-updated.
patel-bhavin Nov 7, 2024
212bb12
Branch was auto-updated.
patel-bhavin Nov 7, 2024
baffbd4
Branch was auto-updated.
patel-bhavin Nov 7, 2024
f6146d6
Branch was auto-updated.
patel-bhavin Nov 12, 2024
60e1cfa
Branch was auto-updated.
patel-bhavin Nov 12, 2024
3a75334
Branch was auto-updated.
patel-bhavin Nov 14, 2024
7315970
Branch was auto-updated.
patel-bhavin Nov 14, 2024
405c6e6
Branch was auto-updated.
patel-bhavin Nov 14, 2024
30fae6b
Branch was auto-updated.
patel-bhavin Nov 14, 2024
05ed9db
Branch was auto-updated.
patel-bhavin Nov 19, 2024
49096d9
Branch was auto-updated.
patel-bhavin Nov 19, 2024
9ac608a
Branch was auto-updated.
patel-bhavin Nov 19, 2024
f026234
Branch was auto-updated.
patel-bhavin Nov 20, 2024
170e119
Branch was auto-updated.
patel-bhavin Nov 20, 2024
bce2482
Branch was auto-updated.
patel-bhavin Dec 2, 2024
99689c0
Branch was auto-updated.
patel-bhavin Dec 2, 2024
f7e35ae
Branch was auto-updated.
patel-bhavin Dec 2, 2024
06a356c
Branch was auto-updated.
patel-bhavin Dec 3, 2024
ac34d12
Branch was auto-updated.
patel-bhavin Dec 3, 2024
1ced58e
Branch was auto-updated.
patel-bhavin Dec 3, 2024
ed95bea
Branch was auto-updated.
patel-bhavin Dec 3, 2024
9d996d5
Branch was auto-updated.
patel-bhavin Dec 3, 2024
1b68a7d
Branch was auto-updated.
patel-bhavin Dec 9, 2024
86d303e
Branch was auto-updated.
patel-bhavin Dec 10, 2024
4dabd5d
Merge branch 'develop' into auditd_sourcetype_update
nasbench Jan 14, 2025
a7fb1c4
Branch was auto-updated.
patel-bhavin Jan 14, 2025
9c937ce
Branch was auto-updated.
patel-bhavin Jan 14, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions data_sources/linux_auditd_add_user.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Linux Auditd Add User
id: 30f79353-e1d2-4585-8735-1e0359559f3f
version: 1
date: '2024-08-08'
date: '2024-08-24'
author: Teoderick Contreras, Splunk
description: Data source object for Linux Auditd Add User Type
source: /var/log/audit/audit.log
sourcetype: linux:audit
source: auditd
sourcetype: auditd
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
Expand Down
6 changes: 3 additions & 3 deletions data_sources/linux_auditd_execve.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Linux Auditd Execve
id: 9ef6364d-cc67-480e-8448-3306829a6a24
version: 1
date: '2024-08-08'
date: '2024-09-24'
author: Teoderick Contreras, Splunk
description: Data source object for Linux Auditd Execve Type
source: /var/log/audit/audit.log
sourcetype: linux:audit
source: auditd
sourcetype: auditd
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
Expand Down
6 changes: 3 additions & 3 deletions data_sources/linux_auditd_path.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Linux Auditd Path
id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d
version: 1
date: '2024-08-08'
date: '2024-09-24'
author: Teoderick Contreras, Splunk
description: Data source object for Linux Auditd Path Type
source: /var/log/audit/audit.log
sourcetype: linux:audit
source: auditd
sourcetype: auditd
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
Expand Down
6 changes: 3 additions & 3 deletions data_sources/linux_auditd_proctitle.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Linux Auditd Proctitle
id: 5a25984a-2789-400a-858b-d75c923e06b1
version: 1
date: '2024-08-08'
date: '2024-09-24'
author: Teoderick Contreras, Splunk
description: Data source object for Linux Auditd Proctitle Type
source: /var/log/audit/audit.log
sourcetype: linux:audit
source: auditd
sourcetype: auditd
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
Expand Down
6 changes: 3 additions & 3 deletions data_sources/linux_auditd_service_stop.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Linux Auditd Service Stop
id: 0643483c-bc62-455c-8d6e-1630e5f0e00d
version: 1
date: '2024-08-08'
date: '2024-09-24'
author: Teoderick Contreras, Splunk
description: Data source object for Linux Auditd Service Stop Type
source: /var/log/audit/audit.log
sourcetype: linux:audit
source: auditd
sourcetype: auditd
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
Expand Down
6 changes: 3 additions & 3 deletions data_sources/linux_auditd_syscall.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
name: Linux Auditd Syscall
id: 4dff7047-0d43-4096-bb3f-b756c889bbad
version: 1
date: '2024-08-08'
date: '2024-09-24'
author: Teoderick Contreras, Splunk
description: Data source object for Linux Auditd Syscall Type
source: /var/log/audit/audit.log
sourcetype: linux:audit
source: auditd
sourcetype: auditd
configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules
supported_TA:
- name: Splunk Add-on for Unix and Linux
Expand Down
2 changes: 1 addition & 1 deletion macros/linux_auditd.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
definition: sourcetype="linux:audit"
definition: sourcetype="auditd"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environment.
name: linux_auditd
Loading