splunk / contentctl

Splunk Content Control Tool

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

New SSA Content Missing Search Field

pyth0n1c opened this issue · comments

When generating new content with:
python3 contentctl.py -p . new_content -t detection
and choosing SSA instead of ESCU, the generated detection .yml field is missing the search field.