mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-08 18:22:47 +01:00
Wrap parenthesis around correlation filter to allow additional filtering
This commit is contained in:
@@ -5,10 +5,10 @@
|
|||||||
]},
|
]},
|
||||||
{ "name": "actionCorrelate", "description": "actionCorrelateHelp", "icon": "fab fa-searchengin", "target": "",
|
{ "name": "actionCorrelate", "description": "actionCorrelateHelp", "icon": "fab fa-searchengin", "target": "",
|
||||||
"links": [
|
"links": [
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" OR \"{:log.id.uid}\" OR \"{:network.community_id}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.fuid}\" OR \"{:log.id.uid}\" OR \"{:network.community_id}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" OR \"{:log.id.uid}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.fuid}\" OR \"{:log.id.uid}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" OR \"{:network.community_id}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.fuid}\" OR \"{:network.community_id}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.uid}\" OR \"{:network.community_id}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.uid}\" OR \"{:network.community_id}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" | groupby event.module event.dataset",
|
"/#/hunt?q=\"{:log.id.fuid}\" | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.uid}\" | groupby event.module event.dataset",
|
"/#/hunt?q=\"{:log.id.uid}\" | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:network.community_id}\" | groupby event.module event.dataset"
|
"/#/hunt?q=\"{:network.community_id}\" | groupby event.module event.dataset"
|
||||||
|
|||||||
@@ -5,10 +5,10 @@
|
|||||||
]},
|
]},
|
||||||
{ "name": "actionCorrelate", "description": "actionCorrelateHelp", "icon": "fab fa-searchengin", "target": "",
|
{ "name": "actionCorrelate", "description": "actionCorrelateHelp", "icon": "fab fa-searchengin", "target": "",
|
||||||
"links": [
|
"links": [
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" OR \"{:log.id.uid}\" OR \"{:network.community_id}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.fuid}\" OR \"{:log.id.uid}\" OR \"{:network.community_id}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" OR \"{:log.id.uid}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.fuid}\" OR \"{:log.id.uid}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" OR \"{:network.community_id}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.fuid}\" OR \"{:network.community_id}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.uid}\" OR \"{:network.community_id}\" | groupby event.module event.dataset",
|
"/#/hunt?q=(\"{:log.id.uid}\" OR \"{:network.community_id}\") | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.fuid}\" | groupby event.module event.dataset",
|
"/#/hunt?q=\"{:log.id.fuid}\" | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:log.id.uid}\" | groupby event.module event.dataset",
|
"/#/hunt?q=\"{:log.id.uid}\" | groupby event.module event.dataset",
|
||||||
"/#/hunt?q=\"{:network.community_id}\" | groupby event.module event.dataset"
|
"/#/hunt?q=\"{:network.community_id}\" | groupby event.module event.dataset"
|
||||||
|
|||||||
Reference in New Issue
Block a user