Compare commits

...
Author SHA1 Message Date
Mike Reeves 3304aff62b Note that an oai query also needs the agentic assistant
SOC (securityonion-soc#1363) now hides a query licensed for oai unless the
assistant is enabled and agentic, so the query editor's license help says so.

Claude-Session: https://claude.ai/code/session_01SZLcwj68A2wLo3F8TGKsLP
2026-10-07 08:56:44 -04:00
Mike Reeves 7469d833d1 Add a licensed Group By Assessment, Name alerts query
Groups alerts by the AI triage assessment, keeping untriaged alerts as a
missing bucket. Query entries take an optional license feature, which SOC uses
to hide this one on grids without OnionAI, and the query editor now shows it.
2026-10-06 21:14:25 -04:00
Mike Reeves b11fc6257a Map the AlertTriage and Notifier agents to a model
SOC disables a built-in agent that has no agentMapping entry, so the new
AlertTriage agent and the Notifier it delegates to need one to run.
2026-10-06 20:43:04 -04:00
Jason Ertel d1114a0dae Merge pull request #16300 from Security-Onion-Solutions/jertel/wip
update tick interval desc
2026-10-06 18:41:48 -04:00
Jason Ertel f4b301d71c update tick interval desc 2026-10-06 18:32:49 -04:00
2 changed files with 14 additions and 1 deletions

No files matched your search

+5
View File
@@ -1542,6 +1542,8 @@ soc:
Orchestrator: sonnet@SOAI
Investigator: gemma@SOAI
DetectionEngineer: gemma@SOAI
AlertTriage: gemma@SOAI
Notifier: gemma@SOAI
useMemory: false
useMemoryScanner: false
dontScanBefore: ""
@@ -2522,6 +2524,9 @@ soc:
queries:
- name: 'Group By Name, Module'
query: '* | groupby rule.name event.module* event.severity_label rule.uuid'
- name: 'Group By Assessment, Name'
query: '* | groupby event.so_alerttriage.assessment* rule.name event.severity_label rule.uuid'
license: oai
- name: 'Group By Sensor, Source IP/Port, Destination IP/Port, Name'
query: '* | groupby observer.name source.ip source.port destination.ip destination.port rule.name network.community_id event.severity_label rule.uuid'
- name: 'Group By Source IP, Name'
+9 -1
View File
@@ -937,6 +937,12 @@ soc:
DetectionEngineer:
description: This agent manages detections and their overrides, including tuning noisy rules and authoring rule content.
global: True
AlertTriage:
description: This agent triages alerts autonomously for the Alert Triage automation, ending each run with a report and an assessment of the alert. It can notify through the Notifier but cannot acknowledge alerts or escalate to cases.
global: True
Notifier:
description: This agent sends a single notification on behalf of another agent, such as AlertTriage, and takes no other action.
global: True
useMemory:
description: Enables the Memory system for OnionAI
global: True
@@ -1025,7 +1031,7 @@ soc:
forcedType: int
automationSettings:
tickIntervalSeconds:
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0.
description: How often, in seconds, the automation scheduler checks for automations that are due to run. Must be greater than 0. This value is also the default interval for new automations, however admins can override individual automation intervals to a longer value via the Agent Studio.
global: True
advanced: True
forcedType: int
@@ -1203,6 +1209,8 @@ soc:
- field: showSubtitle
label: Show Query in Dropdown.
forcedType: bool
- field: license
label: Only show on grids licensed for this feature, e.g. oai. An oai query also needs the assistant enabled and agentic. Leave blank to show everywhere.
queryToggleFilters:
description: Customize togglable query filters that apply to all queries. Exclusive toggles will invert the filter if toggled off rather than omitting the filter from the query.
global: True