soc.json stuff

This commit is contained in:
Mike Reeves
2020-10-01 15:23:07 -04:00
parent b423e8d22a
commit cc2f2de5b5

View File

@@ -180,7 +180,7 @@
{ "name": "acknowledged", "filter": "event.acknowledged:true", "enabled": false, "exclusive": true }, { "name": "acknowledged", "filter": "event.acknowledged:true", "enabled": false, "exclusive": true },
{ "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true } { "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true }
], ],
"queries": {{ alert_queries.soc.alerts.queries | json }} "queries": {{ alerts_queries.soc.alerts.queries | json }}
, ,
"actions": [ "actions": [
{ "name": "", "description": "actionHuntHelp", "icon": "fa-crosshairs", "link": "/#/hunt?q=\"{value}\" | groupby event.module event.dataset", "target": "_blank" }, { "name": "", "description": "actionHuntHelp", "icon": "fa-crosshairs", "link": "/#/hunt?q=\"{value}\" | groupby event.module event.dataset", "target": "_blank" },