Source types for the Splunk Add-on for GitHub
The Splunk Add-on for GitHub has the following sourcetypes.
Source type | Event type | CIM data models |
---|---|---|
github:enterprise:audit
|
github_authentication
|
Authentication |
github_all_changes
|
Change | |
github_account_changes
|
Change Account Management | |
github_audit_changes
|
Change Auditing Changes | |
github:cloud:audit
|
github_alert
|
Alert |
github_all_changes
|
Change | |
github_account_changes
|
Change Account Management | |
github_audit_changes
|
Change Auditing Changes | |
github:cloud:user
|
github_cloud_user
|
User |
github:cloud:code:scanning:alerts
|
github_code_scanning_alerts
|
Alert |
github:cloud:dependabot:scanning:alerts
|
github_dependabot_scanning_alerts
|
Alert |
github:cloud:secret:scanning:alerts
|
github_secret_scanning_alerts
|
Alert |
Lookups for the Splunk Add-on for GitHub | CIM Compatibility for GitHub Cloud Audit Logs |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!