diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index bcdccf9ca..e0a5206bc 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1448,11 +1448,11 @@ soc: detectionsEnabled: true inactiveTools: ['toolUnused'] detectionEngineStatusQueries: - - suricata: + suricata: IntegrityFailure: 'tags:so-soc AND soc.fields.error: "integrity check failed; discrepancies found" AND soc.fields.detectionEngine:"suricata"' - - elastalert: + elastalert: IntegrityFailure: 'tags:so-soc AND soc.fields.error: "integrity check failed; discrepancies found" AND soc.fields.detectionEngine:"elastalert"' - - strelka: + strelka: IntegrityFailure: 'tags:so-soc AND soc.fields.error: "integrity check failed; discrepancies found" AND soc.fields.detectionEngine:"strelka"' tools: - name: toolKibana