Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Description

SAM - SOC Alert Manager

Covers all your SOC's needs for the analysts to get to work.

How 2 Install

  1. Download gitrepo as zip

  2. Move zip to root folder of the app you wish to install SAM on top off

  3. Unzip to full paths

  4. go to /opt/splunk/etc/apps/%appname%/local

  5. Edit the props.conf file

Create the file if it does not exist. Add the following lines to the file:

[audittrail]
EXTRACT-ss_name_sam = \",\sss_name=\"(?<ss_name_sam>.+?)\",\ssid=\"

Beware

If the "[audittrail]" section already exists, add the second line to the existing section.

  1. Reload app

  2. Files should now be placed in the required folders.

About

SOC Alert Manager - Covers all your SOC's needs for the analysts to get to work.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages