soc.json stuff

This commit is contained in:
Mike Reeves
2020-10-01 15:23:07 -04:00
parent b423e8d22a
commit cc2f2de5b5

View File

@@ -180,7 +180,7 @@
{ "name": "acknowledged", "filter": "event.acknowledged:true", "enabled": false, "exclusive": true },
{ "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true }
],
"queries": {{ alert_queries.soc.alerts.queries | json }}
"queries": {{ alerts_queries.soc.alerts.queries | json }}
,
"actions": [
{ "name": "", "description": "actionHuntHelp", "icon": "fa-crosshairs", "link": "/#/hunt?q=\"{value}\" | groupby event.module event.dataset", "target": "_blank" },