Merge pull request #6720 from Security-Onion-Solutions/kilo

Add case template to eval install types; also improve clarity of case queries
This commit is contained in:
Jason Ertel
2021-12-29 11:41:06 -05:00
committed by GitHub
2 changed files with 3 additions and 2 deletions

View File

@@ -1,6 +1,7 @@
elasticsearch:
templates:
- so/so-beats-template.json.jinja
- so/so-case-template.json.jinja
- so/so-common-template.json.jinja
- so/so-firewall-template.json.jinja
- so/so-flow-template.json.jinja

View File

@@ -1,5 +1,5 @@
[
{ "name": "Open Cases", "query": "!case.status:Closed AND !case.category:Template" },
{ "name": "Closed Cases", "query": "case.status:Closed AND !case.category:Template" },
{ "name": "Open Cases", "query": "NOT case.status:Closed AND NOT case.category:Template" },
{ "name": "Closed Cases", "query": "case.status:Closed AND NOT case.category:Template" },
{ "name": "Templates", "query": "case.category:Template" }
]