SAM - SOC Alert Manager
Covers all your SOC's needs for the analysts to get to work.
-
Download gitrepo as zip
-
Move zip to root folder of the app you wish to install SAM on top off
-
Unzip to full paths
-
go to /opt/splunk/etc/apps/%appname%/local
-
Edit the props.conf file
Create the file if it does not exist. Add the following lines to the file:
[audittrail]
EXTRACT-ss_name_sam = \",\sss_name=\"(?<ss_name_sam>.+?)\",\ssid=\"
If the "[audittrail]" section already exists, add the second line to the existing section.
-
Reload app
-
Files should now be placed in the required folders.