mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Merge pull request #8773 from Security-Onion-Solutions/fix/soc2.4
fix some soc defaults
This commit is contained in:
@@ -659,7 +659,7 @@ soc:
|
||||
queryBaseFilter:
|
||||
queryToggleFilters:
|
||||
- name: caseExcludeToggle
|
||||
filter: NOT _index:\"*:so-case*\"
|
||||
filter: 'NOT _index:"*:so-case*"'
|
||||
enabled: true
|
||||
queries:
|
||||
- name: Default Query
|
||||
@@ -1375,7 +1375,7 @@ soc:
|
||||
- source.ip
|
||||
queryBaseFilter:
|
||||
queryToggleFilters:
|
||||
- name: caseExcludeToggle,
|
||||
- name: caseExcludeToggle
|
||||
filter: 'NOT _index:"*:so-case*"'
|
||||
enabled: true
|
||||
queries:
|
||||
@@ -1601,7 +1601,7 @@ soc:
|
||||
- so_case.severity
|
||||
- so_case.assigneeId
|
||||
- so_case.createTime
|
||||
queryBaseFilter: '_index:\"*:so-case\" AND so_kind:case'
|
||||
queryBaseFilter: '_index:"*:so-case" AND so_kind:case'
|
||||
queryToggleFilters: []
|
||||
queries:
|
||||
- name: Open Cases
|
||||
|
||||
Reference in New Issue
Block a user