mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-24 18:03:10 +01:00
Add event.module to default alert query
This commit is contained in:
@@ -171,7 +171,7 @@
|
||||
"queryPrefix": "event.dataset:alert AND",
|
||||
"querySuffix": "",
|
||||
"queries": [
|
||||
{ "name": "Group By Name", "query": "* | groupby rule.name event.severity_label" },
|
||||
{ "name": "Group By Name, Module", "query": "* | groupby rule.name event.module event.severity_label" },
|
||||
{ "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name network.community_id event.severity_label" },
|
||||
{ "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name event.severity_label" },
|
||||
{ "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.name event.severity_label" },
|
||||
|
||||
Reference in New Issue
Block a user