Skip to content

Commit 81bdcbb

Browse files
committed
deprecated macros were not copied over during PORT operation. Fix that.
1 parent 2b10ef9 commit 81bdcbb

73 files changed

Lines changed: 507 additions & 197 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

macros/deprecated/aws_config.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
1-
definition: sourcetype=aws:config
2-
description: customer specific splunk configurations(eg- index, source, sourcetype).
3-
Replace the macro definition with configurations for your Splunk Environment.
41
name: aws_config
2+
id: f14bfb6b-7b06-4cb6-beef-59f584b3dffd
3+
version: 1
4+
creation_date: '2020-04-30'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment.
8+
definition: sourcetype=aws:config
Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
1-
definition: sourcetype="aws:description"
2-
description: customer specific splunk configurations(eg- index, source, sourcetype).
3-
Replace the macro definition with configurations for your Splunk Environment.
41
name: aws_description
2+
id: 37b90e53-76f4-4cc9-8b74-d2294d80f3f6
3+
version: 1
4+
creation_date: '2020-04-30'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment.
8+
definition: sourcetype="aws:description"
Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
1-
definition: sourcetype="aws:securityhub:firehose"
2-
description: customer specific splunk configurations(eg- index, source, sourcetype).
3-
Replace the macro definition with configurations for your Splunk Environment.
41
name: aws_securityhub_firehose
2+
id: 047a11bf-353a-45cf-86b4-3cf2ee680fdb
3+
version: 1
4+
creation_date: '2020-05-05'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment.
8+
definition: sourcetype="aws:securityhub:firehose"

macros/deprecated/azuread.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
1-
definition: sourcetype=mscs:azure:eventhub
2-
description: customer specific splunk configurations(eg- index, source, sourcetype).
3-
Replace the macro definition with configurations for your Splunk Environment.
41
name: azuread
2+
id: 69a46574-72f6-4d76-9502-619e5805f9c1
3+
version: 1
4+
creation_date: '2020-04-30'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environment.
8+
definition: sourcetype=mscs:azure:eventhub
Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
1-
definition: lookup update=true brandMonitoring_lookup domain as query OUTPUT domain_abuse
2-
| search domain_abuse=true
3-
description: This macro limits the output to only domains that are in the brand monitoring
4-
lookup file
51
name: brand_abuse_dns
2+
id: 5ff8a324-d441-40ef-87f2-b220d6301dc2
3+
version: 1
4+
creation_date: '2019-10-16'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: This macro limits the output to only domains that are in the brand monitoring lookup file
8+
definition: lookup update=true brandMonitoring_lookup domain as query OUTPUT domain_abuse | search domain_abuse=true
Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
1-
definition: lookup update=true brandMonitoring_lookup domain as src_user OUTPUT domain_abuse
2-
| search domain_abuse=true
3-
description: This macro limits the output to only domains that are in the brand monitoring
4-
lookup file
51
name: brand_abuse_email
2+
id: 610d5f81-cf1d-4ca6-89d5-2b2c5f8df03d
3+
version: 1
4+
creation_date: '2019-10-16'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: This macro limits the output to only domains that are in the brand monitoring lookup file
8+
definition: lookup update=true brandMonitoring_lookup domain as src_user OUTPUT domain_abuse | search domain_abuse=true
Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
1-
definition: lookup update=true brandMonitoring_lookup domain as urls OUTPUT domain_abuse
2-
| search domain_abuse=true
3-
description: This macro limits the output to only domains that are in the brand monitoring
4-
lookup file
51
name: brand_abuse_web
2+
id: 9113796e-72df-4536-b7db-9dd1cbfc9923
3+
version: 1
4+
creation_date: '2019-10-16'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: This macro limits the output to only domains that are in the brand monitoring lookup file
8+
definition: lookup update=true brandMonitoring_lookup domain as urls OUTPUT domain_abuse | search domain_abuse=true

macros/deprecated/cloud_api_calls_from_previously_unseen_user_roles_activity_window.yml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1+
name: cloud_api_calls_from_previously_unseen_user_roles_activity_window
2+
id: 13fef53a-3ab4-4656-bda0-4c9183cb88be
3+
version: 1
4+
creation_date: '2020-08-20'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
17
description: Use this macro to determine how far back you should be checking for new commands from user roles
28
definition: '"-70m@m"'
3-
name: cloud_api_calls_from_previously_unseen_user_roles_activity_window
Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1-
definition: sourcetype="aws:cloudwatchlogs:eks"
2-
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environment.
31
name: cloudwatch_eks
2+
id: 16c38950-13af-4636-b6aa-bcbdfeda1f69
3+
version: 1
4+
creation_date: '2020-04-30'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environment.
8+
definition: sourcetype="aws:cloudwatchlogs:eks"
Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1-
definition: sourcetype=aws:cloudwatchlogs:vpcflow
2-
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment.
31
name: cloudwatch_vpc
2+
id: 99f810c9-6899-47f6-921a-183c7f71b36d
3+
version: 1
4+
creation_date: '2020-04-30'
5+
modification_date: '2026-05-13'
6+
author: Splunk Threat Research Team
7+
description: customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environment.
8+
definition: sourcetype=aws:cloudwatchlogs:vpcflow

0 commit comments

Comments
 (0)