GCP GCR Container Uploaded


This search show information on uploaded containers including source user, account, action, bucket name event name, http user agent, message and destination path.


GCP GCR Container Uploaded Help

You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a subpub subscription to be imported to Splunk. You must also install Cloud Infrastructure data model. Please also customize the container_implant_gcp_detection_filter macro to filter out the false positives.


Open in Search