More json for soc

This commit is contained in:
Mike Reeves
2020-10-01 17:00:25 -04:00
parent 5653828154
commit 63be0734c9

View File

@@ -1,6 +1,6 @@
soc:
alerts:
queries: [
hunt:
actions: [
{ "name": "Group By Name, Module", "query": "* | groupby rule.name rule.uuid event.module event.severity_label" },
{ "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name rule.uuid network.community_id event.severity_label" },
{ "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name rule.uuid event.severity_label" },