Skip to content

Commit 2bbcdd5

Browse files
authored
Merge pull request #3484 from splunk/cisco_slashn
Cisco slashn
2 parents 45af4de + 1411dac commit 2bbcdd5

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

detections/network/cisco_secure_firewall___blacklisted_ssl_certificate_fingerprint.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -51,9 +51,7 @@ drilldown_searches:
5151
earliest_offset: $info_min_time$
5252
latest_offset: $info_max_time$
5353
rba:
54-
message: >
55-
Suspicious SSL certificate fingerprint ($SSL_CertFingerprint$) used in connections
56-
[ListingReason: $Reasons$]
54+
message: Suspicious SSL certificate fingerprint - [$SSL_CertFingerprint$] used in connections [ListingReason - $Reasons$] from $src_ip$
5755
risk_objects:
5856
- field: src_ip
5957
type: system

0 commit comments

Comments
 (0)