Giter Site home page Giter Site logo

ta-microsoft-windefender's People

Contributors

inspired avatar pdoconnell avatar

Stargazers

 avatar  avatar  avatar

Watchers

 avatar

ta-microsoft-windefender's Issues

Splunk Cloud Support

v1.0.6 is available for Splunk Cloud but v1.0.8 fails validation checks. The only failures are the permissions on the tgz/spl file - file objects need the execute bit removed. Unpacking the tarball and removing the execute bit from files allows it to pass the validator.

SplunkCloud-TA-microsoft-windefender.pdf

Splunk Windows TA renaming

Not and issue with this app but the Splunk_TA_windows has a rename for this sourcetype which causes your sourcetype not not to appear. Thought it would be worth calling out in the readme.

fix create/edit:
Splunk_TA_windows/local/props.conf

[XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational]
rename = xmlwineventlog
disabled = true

[XmlWinEventLog:Microsoft-Windows-Defender/Operational]
rename = xmlwineventlog
disabled = true

[WinEventLog:Microsoft-Windows-Defender/Operational]
rename = wineventlog
disabled = true

[WinEventLog:Microsoft-Windows-Windows Defender/Operational]
rename = wineventlog
disabled = true

EVAL-Feature_Name

While going through the error/warning messages within my Splunk environment, i noticed following warning message which appears quite a number of times in a day.

"Invalid eval expression for 'EVAL-Feature_Name' in stanza [XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational]. The expression is malformed. Expected )"

The currepsonding calulated field expression seem to be incomplete
EVAL-Feature_Name = case(Feature_Name="%%802",

Error when attempting to configure TA after installation in Splunk Cloud

https://splunkbase.splunk.com/app/3734

I was able to self-serve install the above app, TA for Microsoft Windows Defender. However, when I attempt to configure it, I get a 404 error when accessing it; https://.splunkcloud.com/en-US/app/TA-microsoft-windefender/home

In the Internal Spunk logs I see the below:

2020-08-27 23:22:47,040 INFO [5f484046f87f21fc02a1d0] error:311 - Masking the original 404 message: 'Splunk cannot find the "None" view.' with 'Page not found!' for security reasons

2020-08-27 23:22:47,039 WARNING [5f484046f87f21fc02a1d0] appnav:399 - An unknown view name "apn_certificate" is referenced in the navigation definition for "TA-microsoft-windefender".

2020-08-27 23:22:47,038 WARNING [5f484046f87f21fc02a1d0] appnav:399 - An unknown view name "mobile_apps" is referenced in the navigation definition for "TA-microsoft-windefender".

2020-08-27 23:22:47,038 WARNING [5f484046f87f21fc02a1d0] appnav:399 - An unknown view name "home" is referenced in the navigation definition for "TA-microsoft-windefender".

2020-08-27 23:22:47,032 INFO [5f484046f87f21fc02a1d0] memoizedviews:89 - PERF - getDigestTime=0.0191s getParsedViewTime=0.001s

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.