mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Merge pull request #6720 from Security-Onion-Solutions/kilo
Add case template to eval install types; also improve clarity of case queries
This commit is contained in:
@@ -1,6 +1,7 @@
|
|||||||
elasticsearch:
|
elasticsearch:
|
||||||
templates:
|
templates:
|
||||||
- so/so-beats-template.json.jinja
|
- so/so-beats-template.json.jinja
|
||||||
|
- so/so-case-template.json.jinja
|
||||||
- so/so-common-template.json.jinja
|
- so/so-common-template.json.jinja
|
||||||
- so/so-firewall-template.json.jinja
|
- so/so-firewall-template.json.jinja
|
||||||
- so/so-flow-template.json.jinja
|
- so/so-flow-template.json.jinja
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
[
|
[
|
||||||
{ "name": "Open Cases", "query": "!case.status:Closed AND !case.category:Template" },
|
{ "name": "Open Cases", "query": "NOT case.status:Closed AND NOT case.category:Template" },
|
||||||
{ "name": "Closed Cases", "query": "case.status:Closed AND !case.category:Template" },
|
{ "name": "Closed Cases", "query": "case.status:Closed AND NOT case.category:Template" },
|
||||||
{ "name": "Templates", "query": "case.category:Template" }
|
{ "name": "Templates", "query": "case.category:Template" }
|
||||||
]
|
]
|
||||||
Reference in New Issue
Block a user