Merge pull request #15492 from Security-Onion-Solutions/mwright/investigate-refactor

Assistant: Investigated Query Toggle Filter
This commit is contained in:
Matthew Wright
2026-02-18 15:04:33 -05:00
committed by GitHub

View File

@@ -2380,6 +2380,10 @@ soc:
exclusive: true
enablesToggles:
- acknowledged
- name: investigated
filter: event.investigated:true
enabled: false
exclusive: false
queries:
- name: 'Group By Name, Module'
query: '* | groupby rule.name event.module* event.severity_label rule.uuid'