Merge pull request #12720 from Security-Onion-Solutions/2.4/detections-defaults

Add default columns
This commit is contained in:
Josh Brower
2024-04-02 09:21:06 -04:00
committed by GitHub

View File

@@ -2033,6 +2033,7 @@ soc:
- so_detection.severity
- so_detection.language
- so_detection.ruleset
- soc_timestamp
queries:
- name: "All Detections"
query: "_id:*"
@@ -2050,6 +2051,8 @@ soc:
query: 'so_detection.language:sigma AND so_detection.content: "*product: windows*"'
- name: "Detection Type - Yara (Strelka)"
query: "so_detection.language:yara"
- name: "Security Onion - Grid Detections"
query: "so_detection.ruleset:securityonion-resources"
detection:
presets:
severity: