Merge pull request #8773 from Security-Onion-Solutions/fix/soc2.4

fix some soc defaults
This commit is contained in:
Josh Patterson
2022-09-19 15:54:25 -04:00
committed by GitHub

View File

@@ -659,7 +659,7 @@ soc:
queryBaseFilter:
queryToggleFilters:
- name: caseExcludeToggle
filter: NOT _index:\"*:so-case*\"
filter: 'NOT _index:"*:so-case*"'
enabled: true
queries:
- name: Default Query
@@ -1375,7 +1375,7 @@ soc:
- source.ip
queryBaseFilter:
queryToggleFilters:
- name: caseExcludeToggle,
- name: caseExcludeToggle
filter: 'NOT _index:"*:so-case*"'
enabled: true
queries:
@@ -1601,7 +1601,7 @@ soc:
- so_case.severity
- so_case.assigneeId
- so_case.createTime
queryBaseFilter: '_index:\"*:so-case\" AND so_kind:case'
queryBaseFilter: '_index:"*:so-case" AND so_kind:case'
queryToggleFilters: []
queries:
- name: Open Cases