Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Refactor proposal] streamline filtering of detection types across all code and Jinja templates

Open
#339 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Refactor
Clarity
Needs clarification
Activity status
Stale
Tech stack
python
Domain
tooling

Research direction

Start by comparing contentctl/output/templates/savedsearches_detections.j2 and savedsearches_baselines.j2, then audit the repeated filtering and Pydantic validation logic mentioned in the discussion. The issue needs a project-wide design for handling Detection and Baseline types; done should mean the filtering is consistent and new detection types cannot be silently omitted.

Written by the indexing model from the issue text.

Description

Casey:

In the jinja2 template we determine detections to include as:

{% if (detection.type == 'TTP' or detection.type == 'Anomaly' or detection.type == 'Hunting' or detection.type == 'Correlation') %}

This works in practice, but I'm concerned with the burden of having to track this filtering logic in multiple places in potentially inconsistent ways. If we added a new detection type, and neglected to change it here, we might silently be excluding new detections from our build

Eric:

We do this type of thing A LOT, including in all the Pydantic Validations.
The initial idea here is to treat Detections differently than Baselines, as you can see in the Jinja2 templates:
https://github.com/splunk/contentctl/blob/390c3727bf83b5af3e50e4ed4434b542a7d8629f/contentctl/output/templates/savedsearches_detections.j2

contentctl/contentctl/output/templates/savedsearches_baselines.j2

Line 6 in 390c372

 {% if (detection.type == 'Baseline') %} 

This comes from a time when a Baseline and a Detection were defined as the same object, I believe.

Let's talk more about how to actually fix this at scale. I also don't like how Baselines and Detections have SO MANY fields in common, but they are totally different objects (that only inherity from SecurityContentObject).

Dominant language
Python
Stars
139
Forks
51
Avg merge
1h 16m
Merged PRs (30d)
3

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from splunk/contentctl

All issues in splunk/contentctl

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.