Refactor and re-enable per-field validation of risk events
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
Research direction
Start by examining the per-field validation behavior and the two named risk-event examples: “Windows Steal Authentication Certificates - ESC1 Abuse” and “Windows Unusual Count Of Disabled Users Failed Auth Using Kerbero.” Determine whether sparse or computed fields should be accepted, and whether validation should be re-enabled or the issue closed without a fix.
Written by the indexing model from the issue text.
Description
- Originally, we tried to enforce that every field seen in an observable must be an attribute in every single risk event
- In practice this does not seem to be the case, for two different reasons
- Sparsely populated fields (some returned search results don't have all fields, and thus those fields don't exist in some risk objects); see the 'dest' field in
Windows Steal Authentication Certificates - ESC1 Abusefor an example - Certain computed fields, (e.g. when user is computed) may not be vailable in the risk event; see
Windows Unusual Count Of Disabled Users Failed Auth Using Kerberofor an example
- Sparsely populated fields (some returned search results don't have all fields, and thus those fields don't exist in some risk objects); see the 'dest' field in
- The former of these possibilities is more confusing and the solution is less clear
- Resolution of this issue may involve closing it w/o fixing
- Dominant language
- Python
- Stars
- 139
- Forks
- 52
- Avg merge
- 1h 16m
- Merged PRs (30d)
- 3
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from splunk/contentctl
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 45/100
splunk/contentctl#468 · 1 comment ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 38/100
splunk/contentctl#461 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 48/100
splunk/contentctl#452 ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
splunk/contentctl#464 · 3 comments ·
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
splunk/contentctl#451 ·
All issues in splunk/contentctl
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
use-agent-os/agent-os#3314 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
BasedHardware/omi#15662 · 1 comment ·
-
documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
AiursoftWeb/AnduinOS-2#19 ·