diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index a78ea88e14..db98b6b2ff 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1893,7 +1893,16 @@ soc: - event_data.destination.host - event_data.destination.port - event_data.process.executable - - event_data.process.pid + - event_data.process.pid + ':strelka:': + - soc_timestamp + - file.name + - file.size + - hash.md5 + - file.source + - file.mime_type + - log.id.fuid + - event.dataset queryBaseFilter: tags:alert queryToggleFilters: - name: acknowledged