GCP GCR Container Uploaded

Description

This search show information on uploaded containers including source user, account, action, bucket name event name, http user agent, message and destination path.

   Help

GCP GCR Container Uploaded Help

You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a subpub subscription to be imported to Splunk. You must also install Cloud Infrastructure data model. Please also customize the container_implant_gcp_detection_filter macro to filter out the false positives.

   Search

Open in Search