Add default columns

This commit is contained in:
DefensiveDepth
2024-04-02 09:13:27 -04:00
parent 65f6b7022c
commit 7f488422b0

View File

@@ -2033,6 +2033,7 @@ soc:
- so_detection.severity
- so_detection.language
- so_detection.ruleset
- soc_timestamp
queries:
- name: "All Detections"
query: "_id:*"
@@ -2050,6 +2051,8 @@ soc:
query: 'so_detection.language:sigma AND so_detection.content: "*product: windows*"'
- name: "Detection Type - Yara (Strelka)"
query: "so_detection.language:yara"
- name: "Security Onion - Grid Detections"
query: "so_detection.ruleset:securityonion-resources"
detection:
presets:
severity: