Skip to content

Commit 421b11d

Browse files
author
Patrick Bareiss
committed
bug fix
1 parent 526468a commit 421b11d

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

detections/cloud/github_enterprise_disable_2FA_requirement.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ search: '`github_enterprise` action=org.disable_two_factor_requirement OR action
2020
| stats count min(_time) as firstTime max(_time) as lastTime by actor, actor_id, actor_is_bot, actor_location.country_code, business, business_id, user_agent, action
2121
| eval user=actor
2222
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
23-
| `github_enterprise_disable_2FA_requirement_filter`'
23+
| `github_enterprise_disable_2fa_requirement_filter`'
2424
how_to_implement: You must ingest GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector.
2525
known_false_positives: unknown
2626
references:

detections/cloud/github_organizations_disable_2FA_requirement.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ search: '`github_organizations` vendor_action=org.disable_two_factor_requirement
1919
| stats count min(_time) as firstTime max(_time) as lastTime by actor, actor_id, actor_ip, actor_is_bot, actor_location.country_code, business, business_id, org, org_id, user_agent, vendor_action
2020
| eval user=actor
2121
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
22-
| `github_organizations_disable_2FA_requirement_filter`'
22+
| `github_organizations_disable_2fa_requirement_filter`'
2323
how_to_implement: You must ingest GitHub Organizations logs using Splunk Add-on for Github using a Personal Access Token https://docs.splunk.com/Documentation/AddOns/released/GitHub/Configureinputs .
2424
known_false_positives: unknown
2525
references:

0 commit comments

Comments
 (0)