Files
securityonion/salt/soc/files/soc/cases.queries.json

7 lines
531 B
JSON

[
{ "name": "Open Cases", "query": "NOT so_case.status:closed AND NOT so_case.category:template" },
{ "name": "Closed Cases", "query": "so_case.status:closed AND NOT so_case.category:template" },
{ "name": "My Open Cases", "query": "NOT so_case.status:closed AND NOT so_case.category:template AND so_case.assigneeId:{myId}" },
{ "name": "My Closed Cases", "query": "so_case.status:closed AND NOT so_case.category:template AND so_case.assigneeId:{myId}" },
{ "name": "Templates", "query": "so_case.category:template" }
]