added missing commands from bootstrap file for
threathunting app to work
This commit is contained in:
@@ -231,8 +231,17 @@
|
|||||||
sed -i "s/license_key =/license_key = $MAXMIND_LICENSE/g" /opt/splunk/etc/apps/TA-asngen/local/asngen.conf
|
sed -i "s/license_key =/license_key = $MAXMIND_LICENSE/g" /opt/splunk/etc/apps/TA-asngen/local/asngen.conf
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Replace the props.conf for Sysmon TA and Windows TA
|
||||||
|
# Removed all the 'rename = xmlwineventlog' directives
|
||||||
|
# I know youre not supposed to modify files in "default",
|
||||||
|
# but for some reason adding them to "local" wasnt working
|
||||||
|
cp /vagrant/resources/splunk_server/windows_ta_props.conf /opt/splunk/etc/apps/Splunk_TA_windows/default/props.conf
|
||||||
|
cp /vagrant/resources/splunk_server/sysmon_ta_props.conf /opt/splunk/etc/apps/TA-microsoft-sysmon/default/props.conf
|
||||||
|
|
||||||
# Add custom Macro definitions for ThreatHunting App
|
# Add custom Macro definitions for ThreatHunting App
|
||||||
cp /vagrant/resources/splunk_server/macros.conf /opt/splunk/etc/apps/ThreatHunting/default/macros.conf
|
cp /vagrant/resources/splunk_server/macros.conf /opt/splunk/etc/apps/ThreatHunting/default/macros.conf
|
||||||
|
# Fix props.conf in ThreatHunting App
|
||||||
|
sed -i 's/EVAL-host_fqdn = Computer/EVAL-host_fqdn = ComputerName/g' /opt/splunk/etc/apps/ThreatHunting/default/props.conf
|
||||||
# Fix Windows TA macros
|
# Fix Windows TA macros
|
||||||
mkdir /opt/splunk/etc/apps/Splunk_TA_windows/local
|
mkdir /opt/splunk/etc/apps/Splunk_TA_windows/local
|
||||||
cp /opt/splunk/etc/apps/Splunk_TA_windows/default/macros.conf /opt/splunk/etc/apps/Splunk_TA_windows/local
|
cp /opt/splunk/etc/apps/Splunk_TA_windows/default/macros.conf /opt/splunk/etc/apps/Splunk_TA_windows/local
|
||||||
|
|||||||
Reference in New Issue
Block a user