now - delta
now - delta
(default) if the timestamp is older than 24 hours, or exactly 24 hours ago to comply with API restrictionstime.time()
instead of the datetime
librarydatetime
library timezone calculation issues)NOTE: The prior 1.0.34 release contained an incorrect artifact. The 1.0.35 release is a re-release of 1.0.34 with the correct artifact. Please use 1.0.35 instead of 1.0.34.
- Fixed github issue #32 - checks for headersOut and headersIn and does not include them in the event output if the key is not in the response dictionary
- Improved formatting of event data
- Fixed bug where if events and requests inputs were running at the same time, one would overwrite the state of the last time
- Improved setting and handling of timestamps
- Updated AOB Vendored Libraries to that of the latest AddOnBuilder package used to create the release
- Removed deprecated variables from various inputs that are declared already in helper config
NOTE: This 1.0.34 release contained an incorrect artifact. The 1.0.35 release is a re-release of 1.0.34 with the correct artifact. Please use 1.0.35 instead of 1.0.34.
sigsci_helper.py
to reduce introducing errors into re-used codesigsci_helper.py
to reduce the likelyhood of introducing errors in the shared codesigsci_helper.py
helper.get_check_point()
and helper.set_check_point
. This way going forward the code can see what the last until_time
was to make sure that it does not run overlapping time periodsChanges in the new version:
Updated the endpoint for Events to use the Activity endpoint. This way both Flagged IP Alerts and Agent Alerts will be imported.
1.0.21
Fixed an issue where the Splunk App was not correctly using the multi instance mode. The symptoms would be that everything appears to run correctly but would exit before writing out the events. There is a new field in the Inputs configuration for Interval that does need to be filled in if it is not already.
Fixed an issue where the Splunk App was not correctly using the multi instance mode. The symptoms would be that everything appears to run correctly but would exit before writing out the events. There is a new field in the Inputs configuration for Interval that does need to be filled in if it is not already.
1.0.17
- Fixed requirement for app.conf for Splunk Cloud Support, wasn't correctly fixed in 1.0.16.
1.0.15
1.0.14
New Features:
1.0.16
- Fixed requirement for app.conf for Splunk Cloud Support.
1.0.15
1.0.14
New Features:
1.0.15
1.0.14
New Features:
Bugs Fixed:
New Features:
This release includes improvements for:
1.0.12 Improvements:
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.