Improve Firewall dashboard

This commit is contained in:
Doug Burks
2022-12-21 15:29:09 -05:00
committed by GitHub
parent d7b2c88201
commit 506556f0d2

View File

@@ -1548,7 +1548,7 @@ soc:
query: 'event.dataset:s7* | groupby -sankey event.dataset source.ip destination.ip | groupby event.dataset | groupby source.ip | groupby destination.ip | groupby destination.port'
- name: Firewall
description: Firewall logs
query: 'event.dataset:firewall | groupby rule.action | groupby interface.name | groupby network.transport | groupby source.ip | groupby destination.ip | groupby destination.port'
query: 'event.dataset:firewall | groupby -sankey rule.action interface.name | groupby rule.action | groupby interface.name | groupby network.transport | groupby source.ip | groupby destination.ip | groupby destination.port'
job:
alerts:
advanced: false