wazuh-kibana-app/public/templates/overview-fim.html

162 lines
11 KiB
HTML
Raw Normal View History

2016-09-18 17:20:21 +00:00
<md-content flex layout="column" ng-if="!load && submenuNavItem == 'fim'" ng-controller="overviewFimController">
<md-content flex layout="row">
2016-09-20 08:55:43 +00:00
<div flex="10" layout="column">
2016-09-18 17:20:21 +00:00
<md-card>
2016-09-20 08:55:43 +00:00
<md-card-content>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="72px" vis-type="metric" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:Events),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))"
2016-09-20 08:55:43 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck"'>
</kbn-vis>
</md-card-content>
</md-card>
2016-09-18 17:20:21 +00:00
<md-card>
2016-09-20 08:55:43 +00:00
<md-card-content>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="72px" vis-type="metric" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20AND%20full_log:%22Integrity%20checksum%20changed%22%20NOT%20location:%20syscheck-registry')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:'Changed'),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))"
2016-09-20 08:55:43 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck" AND full_log:"Integrity checksum changed" NOT location: syscheck-registry'>
</kbn-vis>
</md-card-content>
</md-card>
2016-09-18 17:20:21 +00:00
<md-card>
2016-09-20 08:55:43 +00:00
<md-card-content>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="72px" vis-type="metric" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20AND%20full_log:%22was%20deleted%22%20NOT%20location:%20syscheck-registry')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:Deleted),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))"
2016-09-20 08:55:43 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck" AND full_log:"was deleted" NOT location: syscheck-registry'>
</kbn-vis>
</md-card-content>
</md-card>
2016-09-18 17:20:21 +00:00
2016-09-20 08:55:43 +00:00
</div>
<div flex layout="column">
2016-09-18 17:20:21 +00:00
<md-card>
2016-09-20 08:55:43 +00:00
<md-card-content>
<span class="md-headline">Events over time</span>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="280px" vis-type="histogram" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.description,order:desc,orderBy:'1',size:100),schema:group,type:terms),(enabled:!t,id:'3',params:(customInterval:'2h',extended_bounds:(),field:'@timestamp',interval:auto,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,interpolate:linear,mode:overlap,scale:linear,setYExtents:!f,shareYAxis:!t,smoothLines:!t,times:!(),yAxis:()),title:'FIM%20Alerts%20over%20time',type:area))"
2016-09-20 14:20:29 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))"
vis-filter='rule.groups:"syscheck"'>
2016-09-20 08:55:43 +00:00
</md-card-content>
2016-09-18 17:20:21 +00:00
</md-card>
</div>
2016-09-20 08:55:43 +00:00
<div flex="20" layout="column">
2016-09-18 17:20:21 +00:00
<md-card>
2016-09-20 08:55:43 +00:00
<md-card-content>
<span class="md-headline">Top user owners</span>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="100px" vis-type="pie" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:SyscheckFile.uname_after,order:desc,orderBy:'1',size:15),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%2015%20new%20users',type:pie))"
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck"'>
2016-09-20 08:55:43 +00:00
</md-card-content>
2016-09-18 17:20:21 +00:00
</md-card>
<md-card>
2016-09-20 08:55:43 +00:00
<md-card-content>
<span class="md-headline">Top group owners</span>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="100px" vis-type="pie" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:SyscheckFile.gname_after,order:desc,orderBy:'1',size:15),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%2015%20new%20users',type:pie))"
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck"'>
2016-09-20 08:55:43 +00:00
</md-card-content>
2016-09-18 17:20:21 +00:00
</md-card>
2016-09-20 08:55:43 +00:00
</div>
2016-09-18 17:20:21 +00:00
</md-content>
2016-09-20 08:55:43 +00:00
<md-content flex layout="row">
2016-09-18 18:04:01 +00:00
<md-card flex layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{last_file_changed}}</div>
2016-09-18 18:04:01 +00:00
<div class="ng-binding">Last file changed</div>
</md-card-content>
</md-card>
<md-card flex layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{last_file_added}}</div>
2016-09-18 18:04:01 +00:00
<div class="ng-binding">Last file added</div>
</md-card-content>
</md-card>
<md-card flex layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{last_file_deleted}}</div>
2016-09-18 18:04:01 +00:00
<div class="ng-binding">Last file deleted</div>
</md-card-content>
</md-card>
</md-content>
2016-09-20 08:55:43 +00:00
<md-content flex layout="row">
2016-09-18 18:04:01 +00:00
<md-card flex="33">
2016-09-20 08:55:43 +00:00
<md-card-content>
<div class="md-headline">Top changed</div>
2016-11-03 19:52:52 +00:00
<kbn-vis vis-height="190px" vis-type="pie" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:SyscheckFile.path,order:desc,orderBy:'1',size:9),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Changed',type:pie))"
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))"
vis-filter='rule.groups:"syscheck" AND full_log:"Integrity checksum changed" NOT location: syscheck-registry'>
2016-09-20 08:55:43 +00:00
</md-card-content>
2016-09-18 18:04:01 +00:00
</md-card>
2016-09-20 08:55:43 +00:00
2016-09-18 18:04:01 +00:00
<md-card flex="33">
2016-09-20 08:55:43 +00:00
<md-card-content>
<div class="md-headline">Top root related changes</div>
2016-11-03 19:52:52 +00:00
<kbn-vis vis-height="190px" vis-type="pie" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:SyscheckFile.path,order:desc,orderBy:'1',size:9),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Changed',type:pie))"
2016-09-20 08:55:43 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck" AND full_log:"Integrity checksum changed" NOT location: syscheck-registry AND root'>
</md-card-content>
2016-09-18 18:04:01 +00:00
</md-card>
2016-09-20 08:55:43 +00:00
2016-09-18 18:04:01 +00:00
<md-card flex="33">
2016-09-20 08:55:43 +00:00
<md-card-content>
<div class="md-headline">Top world writable</div>
2016-11-03 19:52:52 +00:00
<kbn-vis vis-height="190px" vis-type="pie" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20AND%20_exists_:SyscheckFile.perm_after%20AND%20%20(SyscheckFile.perm_after:%2F%5B0-7%5D%7B5%7D(%5B2367%5D).*%2F)')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:SyscheckFile.path,order:desc,orderBy:'1',size:9),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Files',type:pie))"
2016-09-20 08:55:43 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter='rule.groups:"syscheck" AND _exists_:SyscheckFile.perm_after AND (SyscheckFile.perm_after:/[0-7]{5}([2367]).*/) '>
</md-card-content>
2016-09-18 18:04:01 +00:00
</md-card>
2016-09-20 08:55:43 +00:00
2016-09-18 18:04:01 +00:00
</md-content>
2016-09-20 08:55:43 +00:00
<md-content flex layout="row">
<md-card flex="20" layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{topagent}}</div>
<div class="ng-binding">Top agent</div>
</md-card-content>
</md-card>
<md-card flex="20" layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{toppci}}</div>
<div class="ng-binding">Top PCI Requirement</div>
</md-card-content>
</md-card>
<md-card flex="20" layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{toppermissions}}</div>
<div class="ng-binding">Most common permissions</div>
</md-card-content>
</md-card>
<md-card flex="40" layout="column">
<md-card-content style="text-align: center;">
2016-11-03 19:52:52 +00:00
<div class="metric-value ng-binding" style="font-size: 14pt; overflow-x: hidden;">{{topfile}}</div>
<div class="ng-binding">Most changed file</div>
</md-card-content>
</md-card>
2016-09-20 08:55:43 +00:00
</md-content>
2016-09-20 08:55:43 +00:00
<md-content flex layout="row">
2016-09-18 17:20:21 +00:00
<md-card flex>
<md-card-title>
<md-card-title-text>
2016-09-20 18:29:46 +00:00
<span class="md-headline">Events summary</span>
2016-09-18 17:20:21 +00:00
</md-card-title-text>
</md-card-title>
<md-card-content>
2016-10-04 12:53:09 +00:00
<kbn-vis vis-height="460px" vis-type="table" vis-index-pattern="ossec-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22syscheck%22%20NOT%20location:%20%22syscheck-registry%22')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:Agent,field:AgentName,order:desc,orderBy:'1',size:100),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:File,field:SyscheckFile.path,order:desc,orderBy:'1',size:500),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:Event,field:SyscheckFile.event,order:desc,orderBy:'1',size:10),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Description,field:rule.description,order:desc,orderBy:'1',size:10),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
2016-09-22 12:02:46 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))"
2016-09-20 18:29:46 +00:00
vis-filter='rule.groups:"syscheck" NOT location: "syscheck-registry"'>
</kbn-vis>
2016-09-18 17:20:21 +00:00
</md-card-content>
</md-card>
2016-09-20 08:55:43 +00:00
</md-content>
2016-09-20 14:20:29 +00:00
</md-content>