From 69415a0d8d6685f7cc15298222d4d85d2de9a2b9 Mon Sep 17 00:00:00 2001 From: Doug Burks Date: Wed, 21 Dec 2022 15:34:35 -0500 Subject: [PATCH] Improve Strelka dashboard --- salt/soc/defaults.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 2c7b1a372..ceb94c054 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1407,7 +1407,7 @@ soc: query: 'event.dataset:network_connection | groupby -sankey winlog.computer_name destination.ip destination.port | groupby winlog.computer_name | groupby user.name | groupby process.executable | groupby source.ip | groupby destination.ip | groupby destination.port | groupby destination_geo.organization_name' - name: Strelka description: Strelka file analysis - query: 'event.module:strelka | groupby file.mime_type | groupby file.name | groupby file.source' + query: 'event.module:strelka | groupby file.mime_type | groupby -sankey file.mime_type file.source | groupby file.source | groupby file.name' - name: Zeek Notice description: Zeek notice logs query: 'event.dataset:notice | groupby -sankey notice.note destination.ip | groupby notice.note | groupby notice.message | groupby notice.sub_message | groupby source.ip | groupby destination.ip | groupby destination.port | groupby destination_geo.organization_name'