Merge pull request #16035 from Security-Onion-Solutions/reyesj2/huntquery

update default hunt query
This commit is contained in:
Jorge Reyes
2026-07-02 14:50:59 -05:00
committed by GitHub
+4 -4
View File
@@ -1771,13 +1771,13 @@ soc:
enabled: true
queries:
- name: Default Query
description: Show all events grouped by the observer host
query: '* | groupby observer.name'
showSubtitle: true
- name: Log Type
description: Show all events grouped by module and dataset
query: '* | groupby event.module* event.dataset'
showSubtitle: true
- name: Observer
description: Show all events grouped by the observer host
query: '* | groupby observer.name'
showSubtitle: true
- name: SOC - Auth
description: Users authenticated to SOC grouped by IP address and identity
query: 'event.dataset:kratos.audit AND msg:*authenticated* | groupby http.request.headers.x-real-ip user.name'