Security

Malware Operations CIM, catering for multiple engines and pattern types

stephanbuys
Path Finder

Hi,

I am currently adapting sourcetypes for Trend Micro Products to the the CIM, in order to use them with ES and the CIM app.

The CIM caters for:

  • product
  • vendor
  • product_version
  • signature_version

However, the products I deal with have multiple scanning engines as well as multiple pattern file types. I thus propose some new fields:

  • engine
  • engine_version
  • signature_type
  • signature_version

Perhaps signature_version can then be created using an eval of the specified fields.

Regards,
Stephan

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi Stephan,

good suggestions, we'll look into this for the future. In the meantime, you're probably best off treating each engine version as a different product type for simplicity's sake.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi Stephan,

good suggestions, we'll look into this for the future. In the meantime, you're probably best off treating each engine version as a different product type for simplicity's sake.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...