From bc19cce4c24a2607031c10d7b86bc5c289a78645 Mon Sep 17 00:00:00 2001 From: Doug Burks Date: Thu, 1 Oct 2020 10:00:54 -0400 Subject: [PATCH] Acknowledging an alert may acknowledge more alerts than intended #1426 --- salt/soc/files/soc/soc.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/salt/soc/files/soc/soc.json b/salt/soc/files/soc/soc.json index e919d4b8d..b263761a0 100644 --- a/salt/soc/files/soc/soc.json +++ b/salt/soc/files/soc/soc.json @@ -180,12 +180,12 @@ { "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true } ], "queries": [ - { "name": "Group By Name, Module", "query": "* | groupby rule.name event.module event.severity_label" }, - { "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name network.community_id event.severity_label" }, - { "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name event.severity_label" }, - { "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.name event.severity_label" }, - { "name": "Group By Destination IP, Name", "query": "* | groupby destination.ip rule.name event.severity_label" }, - { "name": "Group By Destination Port, Name", "query": "* | groupby destination.port rule.name event.severity_label" }, + { "name": "Group By Name, Module", "query": "* | groupby rule.gid rule.uuid rule.name event.module event.severity_label" }, + { "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.gid rule.uuid rule.name network.community_id event.severity_label" }, + { "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.gid rule.uuid rule.name event.severity_label" }, + { "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.gid rule.uuid rule.name event.severity_label" }, + { "name": "Group By Destination IP, Name", "query": "* | groupby destination.ip rule.gid rule.uuid rule.name event.severity_label" }, + { "name": "Group By Destination Port, Name", "query": "* | groupby destination.port rule.gid rule.uuid rule.name event.severity_label" }, { "name": "Ungroup", "query": "*" } ], "actions": [