Merge pull request #6792 from Security-Onion-Solutions/kilo

Add case exclusion toggle to Hunt to avoid hunt results getting case …
This commit is contained in:
Jason Ertel
2022-01-07 13:02:27 -05:00
committed by GitHub

View File

@@ -166,7 +166,9 @@
"escalateRelatedEventsEnabled": {{ 'true' if CASE_MODULE == 'soc' else 'false' }}, "escalateRelatedEventsEnabled": {{ 'true' if CASE_MODULE == 'soc' else 'false' }},
"eventFields": {{ hunt_eventfields | json }}, "eventFields": {{ hunt_eventfields | json }},
"queryBaseFilter": "", "queryBaseFilter": "",
"queryToggleFilters": [], "queryToggleFilters": [
{ "name": "caseExcludeToggle", "filter": "NOT _index:so-case*", "enabled": true }
],
"queries": {{ hunt_queries | json }}, "queries": {{ hunt_queries | json }},
"actions": {{ menu_actions | json }} "actions": {{ menu_actions | json }}
}, },