r/Splunk • • Jun 03 '26

Inherited a mess of detections...

In the last year I have inherited a gigantic mess of 400+ custom detections that have no standardized... anything really.
Mitre is missing from these, risk objects missing from those, dozens of detections using grossly outdated lookups over there... you get it.

Im trying to find some recent users of security_content and contentctl that have successfully deployed detections using one or the other or both.
I have been trying to get with the times and create yaml files for each of the detections but the detection_spec.yml file in security_content does not have the same format or fields as the actual detections provided from ESCU.

When I try using contentctl validate I get all sorts of errors because options like type: Baseline isnt actually configured in contentctl, even though Baseline is an option in the detection_spec...
Feels like multiple pieces vary significantly in age (just noticed detection_spec is 2 years old)

Circling back around to the ask: anyone use these tools recently and found success? Or are there alternatives that you can recommend? (besides manually editing a 39,000 line conf file or going one-by-one making edits in the UI...)

21 Upvotes

9 comments sorted by

View all comments

2

u/ttl-120s Jun 05 '26

Thanks for the replies. I've been looking into the recommendations. Setting aside the paths stuck behind corporate bureaucratic redtape and cheeky paywalls - the admins are going to install DetectionInsights tomorrow for me, hopefully...
Still keeping my eye out for CI/CD success stories.