Spec-Zone.ru › Ansible

splunk.es.splunk_correlation_searches модуль – Модуль ресурсов Splunk Enterprise Security Correlation searches

Примечание

Этот модуль является частью коллекции splunk.es (версия 3.0.0).

Возможно, эта коллекция уже установлена, если вы используете пакет ansible. Она не включена в ansible-core. Чтобы проверить установку, выполните ansible-galaxy collection list.

Для установки используйте: ansible-galaxy collection install splunk.es.

Для использования в книге задач укажите: splunk.es.splunk_correlation_searches.

Новая функция в splunk.es 2.1.0

  • Обзор
  • Параметры
  • Примеры
  • Возвращаемые значения

Обзор

  • Этот модуль позволяет создавать, удалять и изменять запросы корреляции Splunk Enterprise Security.
  • Проверено на Splunk Enterprise Server v8.2.3 с установленным Splunk Enterprise Security v7.0.1.

Примечание

У этого модуля есть соответствующий плагин действий.

Псевдонимы: correlation_searches

Параметры

Параметр

Комментарии

config

список / элементы=словарь

Настройка мониторинга файлов и каталогов на системе

annotations

словарь

Добавление контекста из стандартных отраслевых карт кибербезопасности в Splunk Enterprise Security или пользовательских аннотаций

cis20

список / элементы=строка

Укажите аннотации CIS20

custom

список / элементы=словарь

Укажите пользовательские фреймворки и пользовательские аннотации

custom_annotations

список / элементы=строка

Укажите аннотации, связанные с пользовательским фреймворком

framework

строка

Укажите фреймворк аннотаций

kill_chain_phases

список / элементы=строка

Укажите аннотации Kill 10

mitre_attack

список / элементы=строка

Укажите аннотации MITRE ATTACK

nist

список / элементы=строка

Укажите аннотации NIST

app

строка

Приложение Splunk для ассоциации с поиском корреляции

По умолчанию: "SplunkEnterpriseSecuritySuite"

cron_schedule

строка

Введите расписание в формате cron.

Например '*/5 * * * *' (каждые 5 минут) или '0 21 * * *' (каждый день в 21:00).

Поиски в реальном времени используют расписание по умолчанию '*/5 * * * *'.

По умолчанию: "*/5 * * * *"

description

строка

Описание поиска корреляции, оно будет отображаться в поле описания веб-консоли

disabled

логическое

Отключить поиск корреляции

Варианты:

  • false ← (по умолчанию)
  • true

name

строка / обязательно

Имя поиска корреляции

schedule_priority

строка

Повышение приоритета планирования отчета. Установите «Higher», чтобы приоритизировать его выше других поисков с тем же режимом планирования, или «Highest», чтобы приоритизировать его выше других поисков независимо от режима. Используйте с осторожностью.

Варианты:

  • "default" ← (по умолчанию)
  • "higher"
  • "highest"

schedule_window

строка

Позвольте отчету выполняться в любое время в течение окна, открывающегося в запланированное время выполнения, чтобы повысить эффективность, когда существует много одновременно запланированных отчетов. Значение «auto» автоматически определяет оптимальную ширину окна для отчета.

По умолчанию: "0"

scheduling

строка

Управляет способом, которым планировщик вычисляет следующее время выполнения запланированного поиска.

Подробнее: https://docs.splunk.com/Documentation/Splunk/7.2.3/Report/Configurethepriorityofscheduledreports#Real-time_scheduling_and_continuous_scheduling

Варианты:

  • "realtime" ← (по умолчанию)
  • "continuous"

search

строка

Строка поиска SPL

suppress_alerts

логическое

Предотвращать или нет оповещения от этого поиска корреляции

Варианты:

  • false ← (по умолчанию)
  • true

throttle_fields_to_group_by

список / элементы=строка

Введите поля для сопоставления событий для ограничения.

throttle_window_duration

string

Сколько времени игнорировать другие события, соответствующие значениям поля, указанным в Полях для группировки.

time_earliest

string

Начальная временная метка с использованием модификаторов относительного времени.

По умолчанию: "-24h"

time_latest

string

Конечная временная метка с использованием модификаторов относительного времени.

По умолчанию: "now"

trigger_alert

string

Действия по реагированию на заметные события и риски всегда активируются для каждого результата. Выберите, активировать триггер один раз или для каждого результата.

Доступные значения:

  • "once" ← (по умолчанию)
  • "for each result"

trigger_alert_when

string

Повысить приоритет планирования отчета. Установите «Выше», чтобы повысить приоритет над другими поисками с тем же режимом планирования, или «Наивысший», чтобы повысить приоритет над другими поисками независимо от режима. Используйте с осторожностью.

Доступные значения:

  • "number of events" ← (по умолчанию)
  • "number of results"
  • "number of hosts"
  • "number of sources"

trigger_alert_when_condition

string

Условие для передачи в trigger_alert_when

Доступные значения:

  • "greater than" ← (по умолчанию)
  • "less than"
  • "equal to"
  • "not equal to"
  • "drops by"
  • "rises by"

trigger_alert_when_value

string

Значение для передачи в trigger_alert_when

По умолчанию: "10"

ui_dispatch_context

string

Укажите приложение для использования в ссылках, таких как поиск по детализации в заметном событии или ссылки в адаптивном действии по ответу на электронную почту. Если None, используется контекст приложения.

running_config

string

Модуль по умолчанию подключается к удаленному устройству и получает текущую конфигурацию running-config, чтобы использовать её как базу для сравнения с содержимым источника. В некоторых случаях нежелательно, чтобы задача получала текущую running-config для каждой задачи в playbook. Параметр running_config позволяет реализатору передать конфигурацию, которая будет использована как базовая конфигурация для сравнения. Это значение должно содержать вывод, полученный от устройства при выполнении команды.

state

string

Состояние, в котором должна остаться конфигурация.

Доступные значения:

  • "merged" ← (по умолчанию)
  • "replaced"
  • "deleted"
  • "gathered"

Примеры

# Using gathered
# --------------

- name: Gather correlation searches config
  splunk.es.splunk_correlation_searches:
    config:
      - name: Ansible Test
      - name: Ansible Test 2
    state: gathered

# RUN output:
# -----------

# "gathered": [
#     {
#       "annotations": {
#           "cis20": [
#               "test1"
#           ],
#           "custom": [
#               {
#                   "custom_annotations": [
#                       "test5"
#                   ],
#                   "framework": "test_framework"
#               }
#           ],
#           "kill_chain_phases": [
#               "test3"
#           ],
#           "mitre_attack": [
#               "test2"
#           ],
#           "nist": [
#               "test4"
#           ]
#       },
#       "app": "DA-ESS-EndpointProtection",
#       "cron_schedule": "*/5 * * * *",
#       "description": "test description",
#       "disabled": false,
#       "name": "Ansible Test",
#       "schedule_priority": "default",
#       "schedule_window": "0",
#       "scheduling": "realtime",
#       "search": '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
#                 'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
#                 'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
#                 'n.src" as "src" | where "count">=6',
#       "suppress_alerts": false,
#       "throttle_fields_to_group_by": [
#           "test_field1"
#       ],
#       "throttle_window_duration": "5s",
#       "time_earliest": "-24h",
#       "time_latest": "now",
#       "trigger_alert": "once",
#       "trigger_alert_when": "number of events",
#       "trigger_alert_when_condition": "greater than",
#       "trigger_alert_when_value": "10",
#       "ui_dispatch_context": "SplunkEnterpriseSecuritySuite"
#     }
# ]

# Using merged
# ------------

- name: Merge and create new correlation searches configuration
  splunk.es.splunk_correlation_searches:
    config:
      - name: Ansible Test
        disabled: false
        description: test description
        app: DA-ESS-EndpointProtection
        annotations:
          cis20:
            - test1
          mitre_attack:
            - test2
          kill_chain_phases:
            - test3
          nist:
            - test4
          custom:
            - framework: test_framework
              custom_annotations:
                - test5
        ui_dispatch_context: SplunkEnterpriseSecuritySuite
        time_earliest: -24h
        time_latest: now
        cron_schedule: "*/5 * * * *"
        scheduling: realtime
        schedule_window: "0"
        schedule_priority: default
        trigger_alert: once
        trigger_alert_when: number of events
        trigger_alert_when_condition: greater than
        trigger_alert_when_value: "10"
        throttle_window_duration: 5s
        throttle_fields_to_group_by:
          - test_field1
        suppress_alerts: false
        search: >
                '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
                'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
                'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
                'n.src" as "src" | where "count">=6'
    state: merged

# RUN output:
# -----------

# "after": [
#     {
#       "annotations": {
#           "cis20": [
#               "test1"
#           ],
#           "custom": [
#               {
#                   "custom_annotations": [
#                       "test5"
#                   ],
#                   "framework": "test_framework"
#               }
#           ],
#           "kill_chain_phases": [
#               "test3"
#           ],
#           "mitre_attack": [
#               "test2"
#           ],
#           "nist": [
#               "test4"
#           ]
#       },
#       "app": "DA-ESS-EndpointProtection",
#       "cron_schedule": "*/5 * * * *",
#       "description": "test description",
#       "disabled": false,
#       "name": "Ansible Test",
#       "schedule_priority": "default",
#       "schedule_window": "0",
#       "scheduling": "realtime",
#       "search": '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
#                 'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
#                 'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
#                 'n.src" as "src" | where "count">=6',
#       "suppress_alerts": false,
#       "throttle_fields_to_group_by": [
#           "test_field1"
#       ],
#       "throttle_window_duration": "5s",
#       "time_earliest": "-24h",
#       "time_latest": "now",
#       "trigger_alert": "once",
#       "trigger_alert_when": "number of events",
#       "trigger_alert_when_condition": "greater than",
#       "trigger_alert_when_value": "10",
#       "ui_dispatch_context": "SplunkEnterpriseSecuritySuite"
#     },
# ],
# "before": [],

# Using replaced
# --------------

- name: Replace existing correlation searches configuration
  splunk.es.splunk_correlation_searches:
    state: replaced
    config:
      - name: Ansible Test
        disabled: false
        description: test description
        app: SplunkEnterpriseSecuritySuite
        annotations:
          cis20:
            - test1
            - test2
          mitre_attack:
            - test3
            - test4
          kill_chain_phases:
            - test5
            - test6
          nist:
            - test7
            - test8
          custom:
            - framework: test_framework2
              custom_annotations:
                - test9
                - test10
        ui_dispatch_context: SplunkEnterpriseSecuritySuite
        time_earliest: -24h
        time_latest: now
        cron_schedule: "*/5 * * * *"
        scheduling: continuous
        schedule_window: auto
        schedule_priority: default
        trigger_alert: once
        trigger_alert_when: number of events
        trigger_alert_when_condition: greater than
        trigger_alert_when_value: 10
        throttle_window_duration: 5s
        throttle_fields_to_group_by:
          - test_field1
          - test_field2
        suppress_alerts: true
        search: >
                '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
                'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
                'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
                'n.src" as "src" | where "count">=6'

# RUN output:
# -----------

# "after": [
#     {
#         "annotations": {
#             "cis20": [
#                 "test1",
#                 "test2"
#             ],
#             "custom": [
#                 {
#                     "custom_annotations": [
#                         "test9",
#                         "test10"
#                     ],
#                     "framework": "test_framework2"
#                 }
#             ],
#             "kill_chain_phases": [
#                 "test5",
#                 "test6"
#             ],
#             "mitre_attack": [
#                 "test3",
#                 "test4"
#             ],
#             "nist": [
#                 "test7",
#                 "test8"
#             ]
#         },
#         "app": "SplunkEnterpriseSecuritySuite",
#         "cron_schedule": "*/5 * * * *",
#         "description": "test description",
#         "disabled": false,
#         "name": "Ansible Test",
#         "schedule_priority": "default",
#         "schedule_window": "auto",
#         "scheduling": "continuous",
#         "search": '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
#                   'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
#                   'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
#                   'n.src" as "src" | where "count">=6',
#         "suppress_alerts": true,
#         "throttle_fields_to_group_by": [
#             "test_field1",
#             "test_field2"
#         ],
#         "throttle_window_duration": "5s",
#         "time_earliest": "-24h",
#         "time_latest": "now",
#         "trigger_alert": "once",
#         "trigger_alert_when": "number of events",
#         "trigger_alert_when_condition": "greater than",
#         "trigger_alert_when_value": "10",
#         "ui_dispatch_context": "SplunkEnterpriseSecuritySuite"
#     }
# ],
# "before": [
#     {
#         "annotations": {
#             "cis20": [
#                 "test1"
#             ],
#             "custom": [
#                 {
#                     "custom_annotations": [
#                         "test5"
#                     ],
#                     "framework": "test_framework"
#                 }
#             ],
#             "kill_chain_phases": [
#                 "test3"
#             ],
#             "mitre_attack": [
#                 "test2"
#             ],
#             "nist": [
#                 "test4"
#             ]
#         },
#         "app": "DA-ESS-EndpointProtection",
#         "cron_schedule": "*/5 * * * *",
#         "description": "test description",
#         "disabled": false,
#         "name": "Ansible Test",
#         "schedule_priority": "default",
#         "schedule_window": "0",
#         "scheduling": "realtime",
#         "search": '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
#                   'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
#                   'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
#                   'n.src" as "src" | where "count">=6',
#         "suppress_alerts": false,
#         "throttle_fields_to_group_by": [
#             "test_field1"
#         ],
#         "throttle_window_duration": "5s",
#         "time_earliest": "-24h",
#         "time_latest": "now",
#         "trigger_alert": "once",
#         "trigger_alert_when": "number of events",
#         "trigger_alert_when_condition": "greater than",
#         "trigger_alert_when_value": "10",
#         "ui_dispatch_context": "SplunkEnterpriseSecuritySuite"
#     }
# ]

# Using deleted
# -------------

- name: Example to delete the corelation search
  splunk.es.splunk_correlation_searches:
    config:
      - name: Ansible Test
    state: deleted

# RUN output:
# -----------

# "after": [],
# "before": [
#     {
#       "annotations": {
#           "cis20": [
#               "test1"
#           ],
#           "custom": [
#               {
#                   "custom_annotations": [
#                       "test5"
#                   ],
#                   "framework": "test_framework"
#               }
#           ],
#           "kill_chain_phases": [
#               "test3"
#           ],
#           "mitre_attack": [
#               "test2"
#           ],
#           "nist": [
#               "test4"
#           ]
#       },
#       "app": "DA-ESS-EndpointProtection",
#       "cron_schedule": "*/5 * * * *",
#       "description": "test description",
#       "disabled": false,
#       "name": "Ansible Test",
#       "schedule_priority": "default",
#       "schedule_window": "0",
#       "scheduling": "realtime",
#       "search": '| tstats summariesonly=true values("Authentication.tag") as "tag",dc("Authentication.user") as "user_count",dc("Authent'
#                 'ication.dest") as "dest_count",count from datamodel="Authentication"."Authentication" where nodename="Authentication.Fai'
#                 'led_Authentication" by "Authentication.app","Authentication.src" | rename "Authentication.app" as "app","Authenticatio'
#                 'n.src" as "src" | where "count">=6',
#       "suppress_alerts": false,
#       "throttle_fields_to_group_by": [
#           "test_field1"
#       ],
#       "throttle_window_duration": "5s",
#       "time_earliest": "-24h",
#       "time_latest": "now",
#       "trigger_alert": "once",
#       "trigger_alert_when": "number of events",
#       "trigger_alert_when_condition": "greater than",
#       "trigger_alert_when_value": "10",
#       "ui_dispatch_context": "SplunkEnterpriseSecuritySuite"
#     },
# ],

Возвращаемые значения

Общие возвращаемые значения описаны здесь, следующие поля уникальны для данного модуля:

Ключ

Описание

after

список / элементы=строка

Конфигурация в виде структурированных данных после завершения модуля.

Возвращается: при изменении

Пример: ["The configuration returned will always be in the same format of the parameters above."]

before

список / элементы=строка

Конфигурация в виде структурированных данных до вызова модуля.

Возвращается: всегда

Пример: ["The configuration returned will always be in the same format of the parameters above."]

gathered

словарь

Факты о сетевом ресурсе, собранные с удаленного устройства в виде структурированных данных.

Возвращается: когда состояние равно gathered

Пример: "This output will always be in the same format as the module argspec.\n"

Авторы

  • Команда автоматизации безопасности Ansible (@pranav-bhatt) <https://github.com/ansible-security>

Ссылки на коллекцию

  • Система отслеживания задач
  • Репозиторий (источники)

© 2012–2018 Michael DeHaan
© 2018–2024 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/splunk/es/splunk_correlation_searches_module.html

Spec-Zone.ru

Настройки Оффлайн Что нового Помощь О нас
Spec-Zone .ru
спецификации, руководства, описания, API