-
Notifications
You must be signed in to change notification settings - Fork 180
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add example lookup table and data file #446
Conversation
When we update the docs, let's use this as the example. |
@lindsey-w can you approve this? Thx! |
1.0.2.0/23,1814991 | ||
1.0.4.0/22,2077456 | ||
1.0.8.0/21,1814991 | ||
1.0.16.0/20,1814991 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: newline
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry, don't know how to submit after commit without re-review
…n/panther-analysis into k8s-unauthorized-exec-into-pod * 'k8s-unauthorized-exec-into-pod' of github.com:kbroughton/panther-analysis: (21 commits) fix: greynoise object function call not attribute (panther-labs#479) Packs: Cloudflare & Slack (panther-labs#478) feat: bring additional alert_context to AWS rules which had none (panther-labs#472) feat: cyclomatic complexity linting (panther-labs#474) Tweak - Cloudflare L7 DDoS (panther-labs#475) chore: update test badge to use github actions (panther-labs#471) Combine GSuite High/Medium/Low Rule alerts into one (panther-labs#467) kbailey: remove circleCI (panther-labs#470) Kbroughton/make lint action (panther-labs#452) fix: panther specific github actions should not run on forks (panther-labs#469) Remove managed schemas (panther-labs#421) Slack Detections - User (panther-labs#464) Slack Detections - EKM (panther-labs#463) Slack Detections - App (panther-labs#462) Initial Commit - Slack Detections - File (panther-labs#465) Slack Detections - Channel (panther-labs#461) Slack Detections - Workspace/Org (panther-labs#460) Update GSuite Alerts Rules with Rule Name (panther-labs#440) Add example lookup table and data file (panther-labs#446) Slack Data Models & Alert Context Helper (panther-labs#458) ...
Background
Lookup tables and their content can be uploaded using panther_analysis_tool, we need examples to be public.
Changes
Added example lookup table and it's content
Testing
panther_analysis_tool test-lookup-table --path example_cidr_lookup_table.yml