Merge pull request #15161 from Security-Onion-Solutions/jertel/wip

add exclusion toggle
This commit is contained in:
Jason Ertel
2025-10-21 09:36:45 -04:00
committed by GitHub

View File

@@ -1638,6 +1638,9 @@ soc:
- name: socExcludeToggle
filter: 'NOT event.module:"soc"'
enabled: true
- name: onionaiExcludeToggle
filter: 'NOT _index:"*:so-assistant-*"'
enabled: true
queries:
- name: Default Query
description: Show all events grouped by the observer host