mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-09 18:52:52 +01:00
Update default queries
This commit is contained in:
@@ -43,6 +43,7 @@ def compile_yara_rules(rules_dir):
|
||||
"event.dataset": "soc.detections",
|
||||
"log.level": "error",
|
||||
"error.message": error_message,
|
||||
"error.analysis": "syntax error",
|
||||
"detection_type": "yara",
|
||||
"rule.uuid": rule_id,
|
||||
"error.type": "runtime_status"
|
||||
|
||||
Reference in New Issue
Block a user