diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 7c0f78f96..f23c64144 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -659,7 +659,7 @@ soc: queryBaseFilter: queryToggleFilters: - name: caseExcludeToggle - filter: NOT _index:\"*:so-case*\" + filter: 'NOT _index:"*:so-case*"' enabled: true queries: - name: Default Query @@ -1375,7 +1375,7 @@ soc: - source.ip queryBaseFilter: queryToggleFilters: - - name: caseExcludeToggle, + - name: caseExcludeToggle filter: 'NOT _index:"*:so-case*"' enabled: true queries: @@ -1601,7 +1601,7 @@ soc: - so_case.severity - so_case.assigneeId - so_case.createTime - queryBaseFilter: '_index:\"*:so-case\" AND so_kind:case' + queryBaseFilter: '_index:"*:so-case" AND so_kind:case' queryToggleFilters: [] queries: - name: Open Cases