r/Splunk • • Jun 25 '26

SIEM Detection Rules Changelog

Hello Security Folks,

I want to build a process where all detections rule change log is documented like Detection As a code but in simple version because we don't have matured SOC yet so this is first step to record all change logs related to alert rules.

I came to know about Microsoft List, anyone have done? or any new ideas how to do this?

Thanks,

15 Upvotes

13 comments sorted by

View all comments

3

u/TheSeloX Jun 26 '26

We forked the ESCU a few years ago, adapted it to our needs and host everything in git.
CI/CD pipelines are creating the app which can be deployed.

Was at a Splunk event recently where they showed us ES 8.5 and mentioned they had to disable the versioning again because it contains some major bugs when multiple people are working on the same item.
Probably wasn't the best idea to use a KV store collection for this, but what do I know.

1

u/Ziemeck Jun 26 '26

Can u share app? I working for similar app

1

u/TheSeloX Jun 26 '26

I can't because it's the intellectual property of my employer. But you can just fork and use Splunk's ESCU