move rule.uuid after rule.name

This commit is contained in:
Doug Burks
2020-10-01 12:09:52 -04:00
committed by GitHub
parent 4851069a10
commit e836f96c65

View File

@@ -180,12 +180,12 @@
{ "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true } { "name": "escalated", "filter": "event.escalated:true", "enabled": false, "exclusive": true }
], ],
"queries": [ "queries": [
{ "name": "Group By Name, Module", "query": "* | groupby rule.uuid rule.name event.module event.severity_label" }, { "name": "Group By Name, Module", "query": "* | groupby rule.name rule.uuid event.module event.severity_label" },
{ "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.uuid rule.name network.community_id event.severity_label" }, { "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name rule.uuid network.community_id event.severity_label" },
{ "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.uuid rule.name event.severity_label" }, { "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name rule.uuid event.severity_label" },
{ "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.uuid rule.name event.severity_label" }, { "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.name rule.uuid event.severity_label" },
{ "name": "Group By Destination IP, Name", "query": "* | groupby destination.ip rule.uuid rule.name event.severity_label" }, { "name": "Group By Destination IP, Name", "query": "* | groupby destination.ip rule.name rule.uuid event.severity_label" },
{ "name": "Group By Destination Port, Name", "query": "* | groupby destination.port rule.uuid rule.name event.severity_label" }, { "name": "Group By Destination Port, Name", "query": "* | groupby destination.port rule.name rule.uuid event.severity_label" },
{ "name": "Ungroup", "query": "*" } { "name": "Ungroup", "query": "*" }
], ],
"actions": [ "actions": [