diff --git a/salt/soc/files/soc/soc.json b/salt/soc/files/soc/soc.json index ffba0091d..5c3e9868a 100644 --- a/salt/soc/files/soc/soc.json +++ b/salt/soc/files/soc/soc.json @@ -171,7 +171,7 @@ "queryPrefix": "event.dataset:alert AND", "querySuffix": "", "queries": [ - { "name": "Group By Name", "query": "* | groupby rule.name event.severity_label" }, + { "name": "Group By Name, Module", "query": "* | groupby rule.name event.module event.severity_label" }, { "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name network.community_id event.severity_label" }, { "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name event.severity_label" }, { "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.name event.severity_label" },