Splunk® Security Content

Release Notes

This documentation does not apply to the most recent version of Splunk® Security Content. For documentation on the most recent version, go to the latest release.

What's new

Enterprise Security Content Updates v3.56.0 was released on January 12, 2023. It includes the following enhancements.

New analytic story

  • IIS Components

New analytics

  • Windows Disable Windows Event Logging Disable HTTP Logging
  • Windows IIS Components Add New Module
  • Windows IIS Components Get-WebGlobalModule Module Query
  • Windows IIS Components Module Failed to Load
  • Windows IIS Components New Module Added
  • Windows PowerShell Disable Windows Event Logging Disable HTTP Logging
  • Windows PowerShell IIS Components WebGlobalModule Usage

Other updates

  • Update to the CI workflow to upload the summary results to the S3 reporting bucket after a test completes
  • Added risk_index macro, which expands to index=risk in security_content
Last modified on 27 January, 2023
  What's in Splunk Security Content

This documentation applies to the following versions of Splunk® Security Content: 3.56.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters