diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 9ec22b180..8b6bceef0 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -2033,6 +2033,7 @@ soc: - so_detection.severity - so_detection.language - so_detection.ruleset + - soc_timestamp queries: - name: "All Detections" query: "_id:*" @@ -2050,6 +2051,8 @@ soc: query: 'so_detection.language:sigma AND so_detection.content: "*product: windows*"' - name: "Detection Type - Yara (Strelka)" query: "so_detection.language:yara" + - name: "Security Onion - Grid Detections" + query: "so_detection.ruleset:securityonion-resources" detection: presets: severity: