Compare commits

...
Author SHA1 Message Date
Mike Reeves 3304aff62b Note that an oai query also needs the agentic assistant
SOC (securityonion-soc#1363) now hides a query licensed for oai unless the
assistant is enabled and agentic, so the query editor's license help says so.

Claude-Session: https://claude.ai/code/session_01SZLcwj68A2wLo3F8TGKsLP
2026-10-07 08:56:44 -04:00
Mike Reeves 7469d833d1 Add a licensed Group By Assessment, Name alerts query
Groups alerts by the AI triage assessment, keeping untriaged alerts as a
missing bucket. Query entries take an optional license feature, which SOC uses
to hide this one on grids without OnionAI, and the query editor now shows it.
2026-10-06 21:14:25 -04:00
Mike Reeves b11fc6257a Map the AlertTriage and Notifier agents to a model
SOC disables a built-in agent that has no agentMapping entry, so the new
AlertTriage agent and the Notifier it delegates to need one to run.
2026-10-06 20:43:04 -04:00
2 changed files with 13 additions and 0 deletions

No files matched your search

+5
View File
@@ -1542,6 +1542,8 @@ soc:
Orchestrator: sonnet@SOAI
Investigator: gemma@SOAI
DetectionEngineer: gemma@SOAI
AlertTriage: gemma@SOAI
Notifier: gemma@SOAI
useMemory: false
useMemoryScanner: false
dontScanBefore: ""
@@ -2522,6 +2524,9 @@ soc:
queries:
- name: 'Group By Name, Module'
query: '* | groupby rule.name event.module* event.severity_label rule.uuid'
- name: 'Group By Assessment, Name'
query: '* | groupby event.so_alerttriage.assessment* rule.name event.severity_label rule.uuid'
license: oai
- name: 'Group By Sensor, Source IP/Port, Destination IP/Port, Name'
query: '* | groupby observer.name source.ip source.port destination.ip destination.port rule.name network.community_id event.severity_label rule.uuid'
- name: 'Group By Source IP, Name'
+8
View File
@@ -937,6 +937,12 @@ soc:
DetectionEngineer:
description: This agent manages detections and their overrides, including tuning noisy rules and authoring rule content.
global: True
AlertTriage:
description: This agent triages alerts autonomously for the Alert Triage automation, ending each run with a report and an assessment of the alert. It can notify through the Notifier but cannot acknowledge alerts or escalate to cases.
global: True
Notifier:
description: This agent sends a single notification on behalf of another agent, such as AlertTriage, and takes no other action.
global: True
useMemory:
description: Enables the Memory system for OnionAI
global: True
@@ -1203,6 +1209,8 @@ soc:
- field: showSubtitle
label: Show Query in Dropdown.
forcedType: bool
- field: license
label: Only show on grids licensed for this feature, e.g. oai. An oai query also needs the assistant enabled and agentic. Leave blank to show everywhere.
queryToggleFilters:
description: Customize togglable query filters that apply to all queries. Exclusive toggles will invert the filter if toggled off rather than omitting the filter from the query.
global: True