diff --git a/salt/soc/files/soc/soc.json b/salt/soc/files/soc/soc.json index f9dcc5bcc..126577edc 100644 --- a/salt/soc/files/soc/soc.json +++ b/salt/soc/files/soc/soc.json @@ -166,7 +166,9 @@ "escalateRelatedEventsEnabled": {{ 'true' if CASE_MODULE == 'soc' else 'false' }}, "eventFields": {{ hunt_eventfields | json }}, "queryBaseFilter": "", - "queryToggleFilters": [], + "queryToggleFilters": [ + { "name": "caseExcludeToggle", "filter": "NOT _index:so-case*", "enabled": true } + ], "queries": {{ hunt_queries | json }}, "actions": {{ menu_actions | json }} },