contentctl icon indicating copy to clipboard operation
contentctl copied to clipboard

Add import command

Open 0xC0FFEEEE opened this issue 1 year ago • 1 comments

This PR adds support for importing updated searches from an existing savedsearches.conf.

contentctl -p <path_to_content> import -c <path_to_savedsearches.conf>

For the sake of simplicity I opted to read the detection rules, update the search string and write the updated yml back. Whilst it's not perfect, at the very least it's idempotent and only updates detections with updated searches.

I'd value any feedback or contributions (from Splunk and customers) for the next round of updates to this feature branch 🙂

0xC0FFEEEE avatar Nov 25 '23 15:11 0xC0FFEEEE