Skip to content

Commit 4ef0485

Browse files
authored
Update telegram_detected_access_suspicious_api_url.yml
declare macros wineventlog_security
1 parent 602f4da commit 4ef0485

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

detections/endpoint/telegram_detected_access_suspicious_api_url.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ search: `wineventlog_security`
1616
| `telegram_detected_access_suspicious_api_url_filter`
1717
macros:
1818
- telegram_detected_access_suspicious_api_url_filter
19+
- wineventlog_security
1920
how_to_implement: |
2021
Ensure the relevant data source (`Wineventlog:Security`) is ingested into Splunk.
2122
Configure the macro `telegram_detected_access_suspicious_api_url_filter` to filter false positives or noisy data.

0 commit comments

Comments
 (0)