Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Add Event family metaschema keywords to Discovery classes #1331

Closed
wants to merge 16 commits into from

Conversation

pagbabian-splunk
Copy link
Contributor

@pagbabian-splunk pagbabian-splunk commented Jan 31, 2025

Related Issue: #1261

Description of changes:

Added the family metaschema keyword to the various Discovery classes for future organization of related classes.

Delete once you have confirmed the following:

  1. Did you add a single line summary of changes to Unreleased section in the CHANGELOG.md file?

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
…favor of an updated email_activity class.

Updated the email object to include domains, files, urls arrays.
Updated the email_activity class to add the message_trace_uid ID.
Updated the email_activity class to use the references[] for the Trace activity_id instead of the description URL.
Updated the email_activity class description to reflect its SMTP protocol and the possible URLs and files attachments.

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
…on to fail!!

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
…ed an at_least_one constraint on all the to and from attributes. Not all email logs have the 'to' and 'from' but must have at least those or 'smtp_to' and 'smtp_from' in the log.

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
…egory. Updated the Discovery classes with their families of Query, Inventory, State.

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
…_famil

Add back changes for the family keywords to conflicting classes for Discoveryy

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
@pagbabian-splunk pagbabian-splunk added metaschema v1.5.0 Items to be considered for OCSF v1.5.0 labels Jan 31, 2025
@pagbabian-splunk pagbabian-splunk added the enhancement New feature or request label Jan 31, 2025
@pagbabian-splunk pagbabian-splunk deleted the event_family branch February 3, 2025 23:56
@pagbabian-splunk pagbabian-splunk restored the event_family branch February 3, 2025 23:59
@pagbabian-splunk pagbabian-splunk deleted the event_family branch February 4, 2025 00:00
@pagbabian-splunk pagbabian-splunk restored the event_family branch February 4, 2025 00:59
@pagbabian-splunk pagbabian-splunk deleted the event_family branch February 4, 2025 01:00
@pagbabian-splunk pagbabian-splunk restored the event_family branch February 4, 2025 01:23
@pagbabian-splunk pagbabian-splunk deleted the event_family branch February 4, 2025 01:27
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
enhancement New feature or request metaschema v1.5.0 Items to be considered for OCSF v1.5.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant