Classifiers
SplunkPyV2 - Classifier
Added the SplunkPyV2 - Classifier that classifies SplunkPy v2 events into Splunk Finding and Splunk Investigation incident types.
Incident Fields
Splunk Status
Updated the Splunk Status incident field to align with the new Splunk Investigation incident type.
Splunk Urgency
Updated the Splunk Urgency incident field to align with the new Splunk Investigation incident type.
Splunk Sensitivity
Updated the Splunk Sensitivity incident field to align with the new Splunk Investigation incident type.
Splunk Disposition
Updated the Splunk Disposition incident field to align with the new Splunk Investigation incident type.
Splunk Notes
Updated the Splunk Notes incident field to align with the new Splunk Investigation incident type.
Splunk Implicit Finding IDs
New: Added a new incident field - Splunk Implicit Finding IDs.
Splunk Excluded Finding IDs
New: Added a new incident field - Splunk Excluded Finding IDs.
Splunk Intermediate Finding IDs
New: Added a new incident field - Splunk Intermediate Finding IDs.
Splunk Risk Object
New: Added a new incident field - Splunk Risk Object.
Splunk Incident Origin
New: Added a new incident field - Splunk Incident Origin.
Splunk Investigation GUID
New: Added a new incident field - Splunk Investigation GUID.
Splunk Investigation ID
New: Added a new incident field - Splunk Investigation ID.
Splunk Investigation Name
New: Added a new incident field - Splunk Investigation Name.
Splunk Investigation Type
New: Added a new incident field - Splunk Investigation Type.
Splunk Incident IDs
New: Added a new incident field - Splunk Incident IDs.
Splunk ES Event Type
New: Added a new incident field - Splunk ES Event Type.
Splunk Consolidated Findings
New: Added a new incident field - Splunk Consolidated Findings.
Incident Types
- Splunk Investigation
- New: Added a new incident type - Splunk Investigation for Splunk Mission Control investigations ingested by SplunkPy v2.
Integrations
SplunkPy v2
- Added support for fetching Splunk Mission Control investigations.
- Added the Maximum investigations per fetch parameter.
- Added the Event types to fetch parameter.
- Added the First fetch timestamp (Investigations) parameter.
- Added the Investigations fetch query parameter.
- Added the splunk-update-investigation command.
Layouts
- Splunk Investigation
Added the Splunk Investigation layout.
Mappers
Splunk ES - Incoming Mapper
- Added the Splunk ES - Incoming Mapper that maps incoming Splunk Finding and Splunk Investigation fields.
Splunk ES - Outgoing Mapper
Added the Splunk ES - Outgoing Mapper that maps outgoing Splunk Finding and Splunk Investigation fields for mirror-out functionality.
Scripts
SplunkConvertConsolidatedFindingsToMD
Added the SplunkConvertConsolidatedFindingsToMD script that renders Splunk Investigation consolidated findings as a Markdown table.
Related pull requests:
-
44242 Download