Merge pull request #13076 from Security-Onion-Solutions/jertel/eaconfig

provide default columns when viewing SOC logs
This commit is contained in:
Jason Ertel
2024-05-24 08:39:17 -04:00
committed by GitHub

View File

@@ -1271,6 +1271,15 @@ soc:
- netflow.type - netflow.type
- netflow.exporter.version - netflow.exporter.version
- observer.ip - observer.ip
':soc:':
- soc_timestamp
- event.dataset
- source.ip
- soc.fields.requestMethod
- soc.fields.requestPath
- soc.fields.statusCode
- event.action
- soc.fields.error
server: server:
bindAddress: 0.0.0.0:9822 bindAddress: 0.0.0.0:9822
baseUrl: / baseUrl: /