mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Switch soc.json to use lowercase labels in default queries; Also enable the 'Add Case' feature
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
[
|
||||
{ "name": "Open Cases", "query": "NOT case.status:Closed AND NOT case.category:Template" },
|
||||
{ "name": "Closed Cases", "query": "case.status:Closed AND NOT case.category:Template" },
|
||||
{ "name": "Templates", "query": "case.category:Template" }
|
||||
{ "name": "Open Cases", "query": "NOT case.status:closed AND NOT case.category:template" },
|
||||
{ "name": "Closed Cases", "query": "case.status:closed AND NOT case.category:template" },
|
||||
{ "name": "Templates", "query": "case.category:template" }
|
||||
]
|
||||
@@ -207,6 +207,7 @@
|
||||
"escalateEnabled": false,
|
||||
"escalateRelatedEventsEnabled": false,
|
||||
"viewEnabled": true,
|
||||
"createLink": "/case/create",
|
||||
"eventFields": {{ cases_eventfields | json }},
|
||||
"queryBaseFilter": "_index:\"*:so-case\" AND kind:case",
|
||||
"queryToggleFilters": [
|
||||
|
||||
Reference in New Issue
Block a user