From 63be0734c9499f5457acf5f7c8bf56ea1c0a658c Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Thu, 1 Oct 2020 17:00:25 -0400 Subject: [PATCH] More json for soc --- salt/soc/files/soc/hunt.actions.default.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/salt/soc/files/soc/hunt.actions.default.yaml b/salt/soc/files/soc/hunt.actions.default.yaml index 69514fe94..4f2a07f53 100644 --- a/salt/soc/files/soc/hunt.actions.default.yaml +++ b/salt/soc/files/soc/hunt.actions.default.yaml @@ -1,6 +1,6 @@ soc: - alerts: - queries: [ + hunt: + actions: [ { "name": "Group By Name, Module", "query": "* | groupby rule.name rule.uuid event.module event.severity_label" }, { "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name rule.uuid network.community_id event.severity_label" }, { "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name rule.uuid event.severity_label" },