Sigma2SplunkAlert
Sigma2SplunkAlert copied to clipboard
Feature Request: search by index time
Hi Patrick
Would it be nice to give one the option to search by index time? So no event would go missing if indexed later.
Or did you already implement this feature in another app? Didn't go through the code of your projects related to splunk.
Maybe just adding to search_transformations the option "by_indextime".
Let me know, i would provide the code, as I think we will try to use it like that in the future.
Andi
Hi Andi,
that is a good idea and exactly the idea of search transformations. Everybody can add search transformations as needed and therefore adapt the detection rule to their needs. Thank you for your contribution.
Best regards, Patrick