soc.json stuff

This commit is contained in:
Mike Reeves
2020-10-01 15:20:13 -04:00
parent 1a561f6b12
commit b423e8d22a

View File

@@ -180,7 +180,7 @@
{ "name": "acknowledged", "filter": "event.acknowledged:true", "enabled": false, "exclusive": true },
{ "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true }
],
"queries": {{ alert_queries.soc.alerts.queries}}
"queries": {{ alert_queries.soc.alerts.queries | json }}
,
"actions": [
{ "name": "", "description": "actionHuntHelp", "icon": "fa-crosshairs", "link": "/#/hunt?q=\"{value}\" | groupby event.module event.dataset", "target": "_blank" },