-
Notifications
You must be signed in to change notification settings - Fork 386
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Automated Splunk TA Update 168 - Failing Auth detection #3311
base: develop
Are you sure you want to change the base?
Conversation
This is a distinct PR from #3307, although it appears to be updating the same app. Looks like this datasource was added yesterday: #3308 before 3307 was merged, so 3307 didn't have it in its base branch to update- 3308 did pass unit testing but now this is failing, potentially due to the app update. |
Looks like CIM mapping changed specifically for events from OpenSSH in v10.0 of this TA. While successful logins are being mapped, our example failed login event in this test sample is not being mapped to |
Tracking this bug here: https://github.com/splunk/splunk-add-on-for-unix-and-linux/issues/608 |
This PR contains updates to Splunk TAs made by GitHub Actions workflow.