All Apps and Add-ons

How to download a Splunk Security Essentials' custom content .json from a GitLab private page?

jcfl
Loves-to-Learn Lots

I am working on a partner integration project using Splunk Security Essentials (SSE) with my custom security content.

Locally, I have the security use cases in JSON format that SSE accepts, but I want to do this integration through my private GitLab by uploading these security use cases there. However, there is a need to keep this GitLab private, so I can't just make SSE download the formatted JSON content by simply passing it the URL in the `content_download_url` setting from `essentials_update.conf`.

Is there a setting in the `essentials_update.conf` file, or in some other file that I can also include an access token for my GitLab? If not, what other ways can I download content from this private GitLab page in order to integrate with SSE?

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...