From 15ed5d18f2251a101c1c2f9b78b7125d30fc614f Mon Sep 17 00:00:00 2001 From: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com> Date: Tue, 29 Apr 2025 06:57:56 +0000 Subject: [PATCH] Updated TAs --- contentctl.yml | 4 ++-- data_sources/linux_auditd_add_user.yml | 2 +- data_sources/linux_auditd_execve.yml | 2 +- data_sources/linux_auditd_path.yml | 2 +- data_sources/linux_auditd_proctitle.yml | 2 +- data_sources/linux_auditd_service_stop.yml | 2 +- data_sources/linux_auditd_syscall.yml | 2 +- data_sources/linux_secure.yml | 2 +- 8 files changed, 9 insertions(+), 9 deletions(-) diff --git a/contentctl.yml b/contentctl.yml index eafe50b8ff..b89e4a6ce2 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -77,9 +77,9 @@ apps: - uid: 833 title: Splunk Add-on for Unix and Linux appid: Splunk_TA_nix - version: 10.0.0 + version: 10.1.0 description: description of app - hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-unix-and-linux_1000.tgz + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-unix-and-linux_1010.tgz - uid: 5579 title: Splunk Add-on for CrowdStrike FDR appid: Splunk_TA_CrowdStrike_FDR diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 34e9ca198f..25f854e26c 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 10.1.0 fields: - msg - type diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 9f46c3a637..ae82976145 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 10.1.0 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index e61df5b6d2..20d41768d2 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 10.1.0 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index f4123c4d2e..b5c600862c 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 10.1.0 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 944f34b46b..fecab89130 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 10.1.0 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index 838787f1fe..198bd15b28 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.0.0 + version: 10.1.0 fields: - msg - type diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index 7e6390b41b..69a50b266a 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 9.2.0 + version: 10.1.0 fields: - _time - action