The objective is to interface a SIEM tool such as Splunk in order to be able to perform automated tasks on observables/IOCs or TTPs.
This TA has been designed in such a way that :
If you need any documentation or help, please visit the related Github : https://github.com/LetMeR00t/TA-thehive-cortex
Fix
: #112, adding the possibility to select the backslashes sanitization in the parametersFix
: #102, correlation searches actions in Splunk ES are now fixed and can be used with this TARefactor
: Few code optimisationsNote: You can upgrade from v3.2 to v3.9.0 without the intermediate versions.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.9.0
Fix
: Resolve backfill execution issues for alerts/casesFix
: Resolve tasks event correctlyRefactor
: Upgrade thehive4py library to v2.0.0b11 (revised for Splunk)Note: You can upgrade from v3.2 to v3.8.2 without the intermediate versions.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.8.2
Feature
: Support "links" as extraData coming from TheHive 5.5Fix
: Double identical values issue in inputsNote: You can upgrade from v3.2 to v3.8.1 without the intermediate versions.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.8.1
Feature
: Support the "extraData" options when recovering data from alerts/cases using inputsFeature
: Rationalize inputs by having multipleSelect instead of single one to avoid having too many inputs to configureFeature
: The "customFields" field used in inputs have been rework to make it simplier to search on Splunk and reduce the size of the informationFeature
: Tasks recovered from cases have now their own sourcetype as it's considered as a dedicated object in TheHive (Pages are still linked to their case information)Feature
: Support searchbnf.conf file for custom commands information and auto-completion in SPLAdditional fixes have been provided.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.8.0
Feature
: Add the capability to backfill data from the past using inputs (documentation available on Github for inputs)Feature
: Upgrade splunklibFix
: Format rendering in logsFix
: Token usage in dashboards (#106)Note: You can upgrade from v3.2 to v3.7.0 without the v3.2/v3.3/v3.4/v3.5/v3.6.*.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.7.0
Feature
: Add the capability to remove several keys of the events or truncate large values within an event with a max size parameter for log collectionFix
: warn/warning log errorFix
: Remove a third party visualization not supported anymoreNote: You can upgrade from v3.2 to v3.6.2 without the v3.2/v3.3/v3.4/v3.5.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.6.2
Feature
: Refinement of the composite fields (fields with colons) by adding the possibility to enrich observables information from the Splunk search #79 Feature
: Improve the code/documentation regarding the usage of the fields "th_severity", "th_tlp" and "th_pap" used to set values for an alert/case directly from the search #74 Bug
: An issue was fixed regarding the non processing of remaining alerts when one alert wasn't created (due to a duplication for instance) #78 Bug
: An issue was fixed regarding the exclusion of the alert/case tags from the markdown generated table in the description #77 Bug
: An issue was fixed regarding missing carriage return/newline/separator in the markdown generated table in the description #76 See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.2
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.