All Apps and Add-ons

How to download a Splunk Security Essentials' custom content .json from a GitLab private page?

jcfl
Loves-to-Learn Lots

I am working on a partner integration project using Splunk Security Essentials (SSE) with my custom security content.

Locally, I have the security use cases in JSON format that SSE accepts, but I want to do this integration through my private GitLab by uploading these security use cases there. However, there is a need to keep this GitLab private, so I can't just make SSE download the formatted JSON content by simply passing it the URL in the `content_download_url` setting from `essentials_update.conf`.

Is there a setting in the `essentials_update.conf` file, or in some other file that I can also include an access token for my GitLab? If not, what other ways can I download content from this private GitLab page in order to integrate with SSE?

 

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...