WIP: Updated Detection Mappings, Changed Engine to Language

Detection mappings updated to include the removal of Note and the addition of Tags, Ruleset, and Language.

SOC defaults updated to use language based queries rather than engine and show the language column instead of the engine column in results.
This commit is contained in:
Corey Ogburn committed 2024-02-08 09:44:56 -07:00
1 parent 81a3e95914
commit 29174566f3
2 files changed
+18 -10

No files matched your search

@@ -47,13 +47,21 @@
"isCommunity": {
"type": "boolean"
},
"note": {
"tags": {
"type": "text"
},
"ruleset": {
"ignore_above": 1024,
"type": "keyword"
},
"engine": {
"ignore_above": 1024,
"type": "keyword"
},
"language": {
"ignore_above": 1024,
"type": "keyword"
},
"overrides": {
"properties": {
"type": {
+9 -9
View File
@@ -1769,7 +1769,7 @@ soc:
default:
- so_detection.title
- so_detection.isEnabled
- so_detection.engine
- so_detection.language
- "@timestamp"
queries:
- name: "All Detections"
@@ -1781,11 +1781,11 @@ soc:
- name: "Disabled"
query: "so_detection.isEnabled:false"
- name: "Suricata"
query: "so_detection.engine:suricata"
- name: "ElastAlert"
query: "so_detection.engine:elastalert"
- name: "Strelka"
query: "so_detection.engine:strelka"
query: "so_detection.language:suricata"
- name: "Sigma"
query: "so_detection.language:sigma"
- name: "Yara"
query: "so_detection.language:yara"
detection:
presets:
severity:
@@ -1797,12 +1797,12 @@ soc:
- medium
- high
- critical
engine:
language:
customEnabled: false
labels:
- suricata
- elastalert
- strelka
- sigma
- yara
severityTranslations:
minor: low
major: high