Group by community ID on second alert quick query

This commit is contained in:
Jason Ertel
2020-09-19 08:39:01 -04:00
parent 5b38acb64b
commit fc51c2aef4

View File

@@ -172,7 +172,7 @@
"querySuffix": "",
"queries": [
{ "name": "Group By Name", "query": "* | groupby rule.name event.severity_label" },
{ "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name event.severity_label" },
{ "name": "Group By Sensor, Source IP/Port, Destination IP/Port, Name", "query": "* | groupby observer.name source.ip source.port destination.ip destination.port rule.name network.community_id event.severity_label" },
{ "name": "Group By Source IP, Name", "query": "* | groupby source.ip rule.name event.severity_label" },
{ "name": "Group By Source Port, Name", "query": "* | groupby source.port rule.name event.severity_label" },
{ "name": "Group By Destination IP, Name", "query": "* | groupby destination.ip rule.name event.severity_label" },