diff --git a/salt/soc/files/soc/soc.json b/salt/soc/files/soc/soc.json index 4eabb7c48..bb0402f48 100644 --- a/salt/soc/files/soc/soc.json +++ b/salt/soc/files/soc/soc.json @@ -162,6 +162,7 @@ "ackEnabled": false, "escalateEnabled": true, "escalateRelatedEventsEnabled": {{ 'true' if CASE_MODULE == 'soc' else 'false' }}, + "aggregationActionsEnabled": true, "eventFields": {{ hunt_eventfields | json }}, "queryBaseFilter": "", "queryToggleFilters": [ @@ -182,6 +183,7 @@ "ackEnabled": false, "escalateEnabled": true, "escalateRelatedEventsEnabled": {{ 'true' if CASE_MODULE == 'soc' else 'false' }}, + "aggregationActionsEnabled": false, "eventFields": {{ hunt_eventfields | json }}, "queryBaseFilter": "", "queryToggleFilters": [ @@ -205,6 +207,7 @@ "ackEnabled": true, "escalateEnabled": true, "escalateRelatedEventsEnabled": {{ 'true' if CASE_MODULE == 'soc' else 'false' }}, + "aggregationActionsEnabled": true, "eventFields": {{ alerts_eventfields | json }}, "queryBaseFilter": "event.dataset:alert", "queryToggleFilters": [ @@ -226,6 +229,7 @@ "ackEnabled": false, "escalateEnabled": false, "escalateRelatedEventsEnabled": false, + "aggregationActionsEnabled": false, "viewEnabled": true, "createLink": "/case/create", "eventFields": {{ cases_eventfields | json }},