Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecated mapping yaml for detections #3297

Draft
wants to merge 3 commits into
base: develop
Choose a base branch
from

Conversation

patel-bhavin
Copy link
Contributor

adds a new mapping file for deprecated detections:

  • deprecated_name: Okta Two or More Rejected Okta Pushes
    deprecated_id: d93f785e-4c2c-4262-b8c7-12b77a13fd39
    replacement_name: Okta Multiple Failed MFA Requests For User
    replacement_id: 826dbaae-a1e6-4c8c-b384-d16898956e73
    date: '2025-01-28'
    escu_version: 5.0.0
    migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
    reason: Detections updated to use the new search logic and field names due to the
    TA update

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants