splunk/security_content

Expand CIM Web Datamodel

dluxtron opened this issue · 1 comments

Hey! Not sure if this is the right place to request this.

But, theres a couple of things I'd be keen to have added to the web datamodel.

http_content_type_length

In the detection unusually_long_content_type_length.yml
This could be added to the CIM web datamodel, and if the http_content_type_length was present, the prefiltering could be performed in the root search.
Note, theres already a http_user_agent_length field - hopefully http_content_type_length can be added too?

signature

Proxys block things based on website category, and products like zScaler look for signatures which they block.
Also WAFs
Having the signature field in the web datamodel would be a great addition

action

Can we add prescribed values to this field?
allowed, blocked

Closing as there's an internal JIRA with the correct team open for this now.