-
Notifications
You must be signed in to change notification settings - Fork 129
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Populate standard/default query lib #1201
Comments
As we discussed in a recent group meeting, let's make sure one of the out-of-the-box queries highlights the Suricata events. This would give us a place to highlight the new data even if we don't yet have other fancier visualizations specific to Suricata data. We could use community feedback to adjust this or add alternatives if we don't get it right the first time. My proposal would be:
With the example of the our test data |
Name: Activity Overview |
Name: Unique DNS Queries |
Name: Windows Networking Activity |
Name: HTTP Requests |
Name: Unique Network Connections |
Name: |
Name: File Activity |
Name: HTTP Post Requests |
Name: Show IP Subnets |
These were verified as part of #1081. |
Once we have finished building the query lib, we intend to include some standard queries that most people would find useful. Let's build that starter lib!
The text was updated successfully, but these errors were encountered: