soc.json stuff

This commit is contained in:
Mike Reeves
2020-10-01 15:20:13 -04:00
parent 1a561f6b12
commit b423e8d22a

View File

@@ -180,7 +180,7 @@
{ "name": "acknowledged", "filter": "event.acknowledged:true", "enabled": false, "exclusive": true }, { "name": "acknowledged", "filter": "event.acknowledged:true", "enabled": false, "exclusive": true },
{ "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true } { "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true }
], ],
"queries": {{ alert_queries.soc.alerts.queries}} "queries": {{ alert_queries.soc.alerts.queries | json }}
, ,
"actions": [ "actions": [
{ "name": "", "description": "actionHuntHelp", "icon": "fa-crosshairs", "link": "/#/hunt?q=\"{value}\" | groupby event.module event.dataset", "target": "_blank" }, { "name": "", "description": "actionHuntHelp", "icon": "fa-crosshairs", "link": "/#/hunt?q=\"{value}\" | groupby event.module event.dataset", "target": "_blank" },