You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Feb 3, 2023. It is now read-only.
2,Create tstats based Elastic Source Dedicated,,UI,"Via the UI, create a new dedicated Elastic source: tstats based Elastic source *** constraint: index=* sourcetype=pan:traffic | name: Elastic:tstats:shared | index: network | sourcetype: pan:traffic ***. Creation needs to be successful and a new data source created in the UI"
4
4
3,Create raw based Elastic Source Shared,,UI,"Via the UI, create a new shared Elastic source: raw based Elastic source *** constraint: index=* sourcetype=pan:traffic | name: Elastic:raw:shared | index: network | sourcetype: pan:traffic ***. Creation needs to be successful and a new data source created in the UI"
5
5
4,Create raw based Elastic Source Dedicated,,UI,"Via the UI, create a new dedicated Elastic source: raw based Elastic source *** constraint: index=* sourcetype=pan:traffic | name: Elastic:raw:shared | index: network | sourcetype: pan:traffic ***. Creation needs to be successful and a new data source created in the UI"
6
-
5,Create from based Elastic Source Shared,,UI,"Via the UI, create a new shared Elastic source: from based Elastic source *** constraint: datamodel:Authentication | search user=* | name: Elastic:from:shared | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
7
-
6,Create from based Elastic Source Shared,,UI,"Via the UI, create a new shared Elastic source: from based Elastic source *** constraint: datamodel:Authentication | search user=* | name: Elastic:from:shared | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
8
-
7,Create mstats based Elastic Source Shared,,UI,"Via the UI, create a new shared Elastic source: mstats based Elastic source *** constraint: index=telegraf metric_category=docker | name: Elastic:mstats:shared | index: telegraf | sourcetype: metrics ***. Creation needs to be successful and a new data source created in the UI"
9
-
8,Create mstats based Elastic Source Dedicated,,UI,"Via the UI, create a new dedicated Elastic source: mstats based Elastic source *** constraint: index=telegraf metric_category=docker | name: Elastic:mstats:shared | index: telegraf | sourcetype: metrics ***. Creation needs to be successful and a new data source created in the UI"
10
-
9,Verify Search feature,,UI,"For Elastic Sources, the Search btn when hit generates a Splunk SPL search that is dynamicall built, for each of the Elastic Sources previously created, make sure the search works as expected"
6
+
5,Create from datamodel based Elastic Source Shared,,UI,"Via the UI, create a new shared Elastic source: from based Elastic source *** constraint: datamodel:Authentication | search user=* | name: Elastic:from:shared | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
7
+
6,Create from datamodel based Elastic Source Dedicated,,UI,"Via the UI, create a new dedicated Elastic source: from based Elastic source *** constraint: datamodel:Authentication | search user=* | name: Elastic:from:shared | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
8
+
7,Create from lookup based Elastic Source Shared,,UI,"Create a lookup with a time concept, via the UI Via the UI, create a new shared Elastic source: from based Elastic source *** constraint: lookup:acme_cmdb_lookup.csv | eval _time=strftime(lookupLastUpdated, ""%s"") | name: Elastic:from:lookup:shared | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
9
+
8,Create from lookup based Elastic Source Dedicated,,UI,"Create a lookup with a time concept, via the UI Via the UI, create a new shared Elastic source: from based Elastic source *** constraint: lookup:acme_cmdb_lookup.csv | eval _time=strftime(lookupLastUpdated, ""%s"") | name: Elastic:from:lookup:dedicated | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
10
+
9,Create mstats based Elastic Source Shared,,UI,"Via the UI, create a new shared Elastic source: mstats based Elastic source *** constraint: index=telegraf metric_category=docker | name: Elastic:mstats:shared | index: telegraf | sourcetype: metrics ***. Creation needs to be successful and a new data source created in the UI"
11
+
10,Create mstats based Elastic Source Dedicated,,UI,"Via the UI, create a new dedicated Elastic source: mstats based Elastic source *** constraint: index=telegraf metric_category=docker | name: Elastic:mstats:shared | index: telegraf | sourcetype: metrics ***. Creation needs to be successful and a new data source created in the UI"
12
+
11,Create rest tstats based Elastic Source,,UI,"Via the UI, create a new shared Elastic source: rest tstats based Elastic source *** constraint: index=* sourcetype=pan:traffic | name: Elastic:rest:tstats:shared | index: network | sourcetype: pan:traffic ***. Creation needs to be successful and a new data source created in the UI"
13
+
12,Create rest raw based Elastic Source,,UI,"Via the UI, create a new shared Elastic source: rest raw based Elastic source *** constraint: index=* sourcetype=pan:traffic | name: Elastic:rest:raw:shared | index: network | sourcetype: pan:traffic ***. Creation needs to be successful and a new data source created in the UI"
14
+
13,Create rest from datamodel based Elastic Source,,UI,"Via the UI, create a new shared Elastic source: rest from based Elastic source *** constraint: datamodel:Authentication | search user=* | name: Elastic:rest:from:shared | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
15
+
13,Create rest from lookup based Elastic Source,,UI,"Create a lookup with a time concept, via the UI Via the UI, create a new shared Elastic source: from based Elastic source *** constraint: lookup:acme_cmdb_lookup.csv | eval _time=strftime(lookupLastUpdated, ""%s"") | name: Elastic:rest:from:lookup:dedicated | index: security | sourcetype: authentication ***. Creation needs to be successful and a new data source created in the UI"
16
+
14,Create rest mstats based Elastic Source,,UI,"Via the UI, create a new shared Elastic source: rest mstats based Elastic source *** constraint: index=telegraf metric_category=docker | name: Elastic:rest:mstats:shared | index: telegraf | sourcetype: metrics ***. Creation needs to be successful and a new data source created in the UI"
17
+
15,Verify Search feature,,UI,"For Elastic Sources, the Search btn when hit generates a Splunk SPL search that is dynamicall built, for each of the Elastic Sources previously created, make sure the search works as expected"
0 commit comments