Skip to content

R0SEG0LD/SAM

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Description

SAM - SOC Alert Manager

Covers all your SOC's needs for the analysts to get to work.

How 2 Install

  1. Download gitrepo as zip

  2. Move zip to root folder of the app you wish to install SAM on top off

  3. Unzip to full paths

  4. go to /opt/splunk/etc/apps/%appname%/local

  5. Edit the props.conf file

Create the file if it does not exist. Add the following lines to the file:

[audittrail]
EXTRACT-ss_name_sam = \",\sss_name=\"(?<ss_name_sam>.+?)\",\ssid=\"

Beware

If the "[audittrail]" section already exists, add the second line to the existing section.

  1. Reload app

  2. Files should now be placed in the required folders.

About

SOC Alert Manager - Covers all your SOC's needs for the analysts to get to work.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published