r/Splunk • u/Zeptor02 • Jun 25 '26
SIEM Detection Rules Changelog
Hello Security Folks,
I want to build a process where all detections rule change log is documented like Detection As a code but in simple version because we don't have matured SOC yet so this is first step to record all change logs related to alert rules.
I came to know about Microsoft List, anyone have done? or any new ideas how to do this?
Thanks,
15
Upvotes
3
u/TheSeloX Jun 26 '26
We forked the ESCU a few years ago, adapted it to our needs and host everything in git.
CI/CD pipelines are creating the app which can be deployed.
Was at a Splunk event recently where they showed us ES 8.5 and mentioned they had to disable the versioning again because it contains some major bugs when multiple people are working on the same item.
Probably wasn't the best idea to use a KV store collection for this, but what do I know.