diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 2c7b1a372..ceb94c054 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1407,7 +1407,7 @@ soc: query: 'event.dataset:network_connection | groupby -sankey winlog.computer_name destination.ip destination.port | groupby winlog.computer_name | groupby user.name | groupby process.executable | groupby source.ip | groupby destination.ip | groupby destination.port | groupby destination_geo.organization_name' - name: Strelka description: Strelka file analysis - query: 'event.module:strelka | groupby file.mime_type | groupby file.name | groupby file.source' + query: 'event.module:strelka | groupby file.mime_type | groupby -sankey file.mime_type file.source | groupby file.source | groupby file.name' - name: Zeek Notice description: Zeek notice logs query: 'event.dataset:notice | groupby -sankey notice.note destination.ip | groupby notice.note | groupby notice.message | groupby notice.sub_message | groupby source.ip | groupby destination.ip | groupby destination.port | groupby destination_geo.organization_name'