2017-02-07 17:05:51 +00:00
< md-content ng-if = "submenuNavItem == 'oscap' && _agent" id = "agents-oscap" ng-controller = "oscapController" >
2017-02-13 19:58:44 +00:00
<!-- Kibana search bar -->
2017-07-21 11:51:13 +00:00
< kbn-searchbar class = "wazuh-searchbar" ng-if = "tabView == 'panels'" > < / kbn-searchbar >
2017-06-19 17:00:19 +00:00
< div class = 'uil-ring-css' ng-if = "tabView == 'panels'" ng-show = '!hideRing(13)' > < div > < / div > < / div >
2017-02-13 19:58:44 +00:00
2017-02-10 21:33:49 +00:00
<!-- No results message -->
2017-07-03 15:51:46 +00:00
< md-content flex layout = "row" layout-align = "start start" ng-show = "!results && !loading" ng-if = "tabView == 'panels' && hideRing(13)" >
2017-02-10 21:33:49 +00:00
< md-card flex layout = "column" >
< md-card-content style = "text-align: center;" >
No results for selected time interval
< / md-card-content >
< / md-card >
< / md-content >
2017-02-07 17:05:51 +00:00
<!-- View: Discover -->
2017-07-27 16:24:50 +00:00
< md-content style = "background-color: white" flex layout = "column" layout-align = "start space-around" ng-show = "tabView == 'discover'" >
2017-02-07 17:05:51 +00:00
< kbn-disfull table-height = "1000px;" dis-a = "(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
2017-03-02 17:43:04 +00:00
dis-filter="rule.groups:oscap AND agent.name: {{_agent.name ? _agent.name : '*'}} AND manager.name: {{defaultManager ? defaultManager : '*'}}"
2017-02-07 17:05:51 +00:00
infinite-scroll="true">
< / kbn-disfull >
< / md-content >
2017-08-02 17:05:11 +00:00
< div flex ng-show = "hideRing(13) && results && !loading" ng-if = "tabView == 'panels' && !load" layout = "column" >
2017-01-16 18:27:53 +00:00
< md-progress-linear class = "md-accent" md-mode = "indeterminate" ng-show = "load" > < / md-progress-linear >
2017-07-10 20:56:51 +00:00
< md-content layout = "row" layout-align = "center stretch" class = "no-legend" >
2017-01-16 18:27:53 +00:00
< md-card flex = "20" layout = "column" >
< md-card-content style = "text-align: center;" >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "70px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(field:data.oscap.scan.score,customLabel:'Higher score'),schema:metric,type:max)),listeners:(),params:(fontSize:19,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter = "agent.name: {{_agent.name ? _agent.name : '*'}}" > < / kbn-vis >
2017-01-16 18:27:53 +00:00
< / md-card-content >
< / md-card >
< md-card flex = "20" layout = "column" >
< md-card-content style = "text-align: center;" >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "70px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(field:data.oscap.scan.score,customLabel:'Lower score'),schema:metric,type:min)),listeners:(),params:(fontSize:19,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter = "agent.name: {{_agent.name ? _agent.name : '*'}}" >
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "20" layout = "column" >
< md-card-content style = "text-align: center; margin-top: 6px; " >
2017-08-08 19:06:08 +00:00
< kbn-vis-value style = "margin-top: 6px" vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:data.oscap.scan.score,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "agent.name: {{_agent.name ? _agent.name : '*'}}" > < / kbn-vis-value >
2017-01-16 18:27:53 +00:00
< div class = "ng-binding" > Last score< / div >
< / md-card-content >
< / md-card >
< md-card flex = "40" layout = "column" >
< md-card-content style = "text-align: center;" >
2017-08-08 20:25:32 +00:00
< kbn-vis-value vis-height = "37px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:data.oscap.scan.profile.title,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "data.oscap.check.result: fail AND rule.groups: oscap AND agent.name: {{_agent.name ? _agent.name : '*'}}" > < / kbn-vis-value >
2017-01-16 18:27:53 +00:00
< div class = "ng-binding" > Last scan profile< / div >
< / md-card-content >
< / md-card >
< / md-content >
< md-content layout = "row" layout-align = "center stretch" >
< md-card flex = "25" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Scans< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "154px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.scan.id,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Agents',type:pie))"
2017-02-01 21:06:05 +00:00
vis-filter="agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "25" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Profiles< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "154px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:data.oscap.scan.profile.title,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Profiles',type:pie))"
2017-08-08 20:25:32 +00:00
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "25" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Content< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "154px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.scan.content,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Content',type:pie))"
2017-08-08 20:25:32 +00:00
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "25" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Severity< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "154px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.severity,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Content',type:pie))"
2017-08-08 20:25:32 +00:00
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< / md-content >
2017-02-16 12:51:11 +00:00
< md-content layout = "row" layout-align = "start stretch" >
< md-card flex >
2017-01-16 18:27:53 +00:00
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Daily scans evolution< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-01-17 12:35:41 +00:00
< kbn-vis vis-height = "160px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:oscap%20AND%20agent.name:localCentos')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',customLabel:'Daily scans',extended_bounds:(),field:'@timestamp',interval:d,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,legendPosition:right,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))"
2017-02-01 21:06:05 +00:00
vis-filter="rule.groups: oscap AND oscap.check.result:fail AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< / md-content >
< md-content layout = "row" layout-align = "center stretch" >
< md-card flex = "50" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Top 10 - Alerts< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis class = "vis-expand-leyend" vis-height = "300px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.title,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Top%2020%20failed%20checks',type:pie))"
2017-02-01 21:06:05 +00:00
vis-filter="oscap.check.result: fail AND rule.groups:oscap AND rule.groups: oscap-result AND oscap.check.result:fail AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "50" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Top 10 - High risk alerts< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis class = "vis-expand-leyend" vis-height = "300px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.title,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Top%2020%20failed%20checks',type:pie))"
2017-08-08 20:25:32 +00:00
vis-filter="data.oscap.check.severity: high AND data.oscap.check.result: fail AND rule.groups:oscap AND rule.groups: oscap-result AND data.oscap.check.result:fail AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< / md-content >
2017-07-27 16:24:50 +00:00
< md-content layout = "row" layout-align = "center stretch" class = "no-legend" >
2017-01-16 18:27:53 +00:00
< md-card flex = "100" layout = "column" >
< md-card-content style = "text-align: center;" >
2017-08-08 20:25:32 +00:00
< kbn-vis-value vis-height = "44px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.title,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter = "data.oscap.check.result: fail AND rule.groups:oscap AND agent.name: {{_agent.name ? _agent.name : '*'}}" >
2017-01-16 18:27:53 +00:00
< / kbn-vis-value >
< div class = "ng-binding" > Top alert< / div >
< / md-card-content >
< / md-card >
< / md-content >
< md-content layout-align = "center stretch" >
< md-card flex >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Last alerts< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
2017-08-08 19:06:08 +00:00
< kbn-vis vis-height = "450px" vis-index-pattern = "wazuh-alerts-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:99999),schema:bucket,type:terms),(enabled:!t,id:'3',params:(customLabel:Title,field:data.oscap.check.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:Profile,field:data.oscap.scan.profile.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:'Scan ID',field:data.oscap.scan.id,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Content,field:data.oscap.scan.content,order:desc,orderBy:'1',size:5),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
2017-08-08 20:25:32 +00:00
vis-filter="data.oscap.check.result: fail AND rule.groups: oscap AND agent.name: {{_agent.name ? _agent.name : '*'}}">
2017-01-16 18:27:53 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< / md-content >
< / div >
< / md-content >