2016-09-16 18:44:04 +00:00
< md-content ng-if = "submenuNavItem == 'fim'" ng-if = "_agent" class = "md-padding" >
2016-09-02 10:10:10 +00:00
< div flex ng-controller = "fimController" layout = "column" >
< md-progress-linear class = "md-accent" md-mode = "indeterminate" ng-show = "load" > < / md-progress-linear >
2016-09-22 15:24:30 +00:00
2016-09-02 10:10:10 +00:00
< md-content layout = "row" >
< md-card flex = "40" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Events< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
< kbn-vis vis-height = "100px;" vis-type = "histogram" vis-index-pattern = "ossec-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%20syscheck')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',extended_bounds:(),field:'@timestamp',interval:auto,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))"
2016-09-22 15:24:30 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter="location: syscheck AND {{'AgentName:'+_agent.name}}">
2016-09-02 10:10:10 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "30" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Top users< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
< kbn-vis vis-height = "100px;" vis-type = "pie" vis-index-pattern = "ossec-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:SyscheckFile.uname_after,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'New%20Visualization',type:pie))"
2016-09-22 15:24:30 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter="location: syscheck AND {{'AgentName:'+_agent.name}}">
2016-09-02 10:10:10 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< md-card flex = "30" >
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Top files< / span >
< / md-card-title-text >
< / md-card-title >
< md-card-content >
< kbn-vis vis-height = "100px;" vis-type = "pie" vis-index-pattern = "ossec-*" vis-a = "(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:SyscheckFile.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'New%20Visualization',type:pie))"
2016-09-22 15:24:30 +00:00
vis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))" vis-filter="location: syscheck AND {{'AgentName:'+_agent.name}}">
2016-09-02 10:10:10 +00:00
< / kbn-vis >
< / md-card-content >
< / md-card >
< / md-content >
2016-09-22 15:24:30 +00:00
< div layout = "row" layout-align = "space-between stretch" ng-show = "false" >
2016-09-02 10:10:10 +00:00
< md-input-container layout = "row" class = "sideNavBox" flex = "40" >
< label for = "searchBox" > Search< / label >
< input type = "text" id = "searchBox" ng-model = "$parent._fileSearch" ng-change = "fileSearchFilter($parent._fileSearch)" flex >
< / md-input-container >
< div flex = "40" > < / div >
2016-09-20 08:55:43 +00:00
< md-content flex = "40" class = "subNavLine" layout = "row" layout-align = "end center" ng-show = "isWindows" >
< md-button ng-click = "changeType()" class = "md-primary" ng-class = "!$parent.showFilesRegistry ? 'button-disabled' : 'button-active'" >
Files
< / md-button >
< md-button ng-click = "changeType()" class = "md-primary" ng-class = "$parent.showFilesRegistry ? 'button-disabled' : 'button-active'" >
Registry keys
< / md-button >
< / md-content >
2016-09-13 08:43:38 +00:00
< md-input-container style = "margin-top: 12px;" flex = "20" >
2016-09-02 10:10:10 +00:00
< md-select id = "eventBox" ng-model = "$parent._fimEvent" ng-change = "fileEventFilter($parent._fimEvent)" aria-label = "Filter by event" >
2016-09-13 08:43:38 +00:00
< md-option value = "all" > Filter events< / md-option >
2016-09-02 10:10:10 +00:00
< md-option value = "added" > Added< / md-option >
< md-option value = "modified" > Modified< / md-option >
< md-option value = "readded" > Re-added< / md-option >
< md-option value = "deleted" > Deleted< / md-option >
< / md-select >
< / md-input-container >
2016-09-22 15:24:30 +00:00
< / div >
< div layout = "row" layout-align = "space-between stretch" >
2016-09-23 08:03:25 +00:00
< md-card flex = "100" >
2016-09-22 15:24:30 +00:00
< md-card-title >
< md-card-title-text >
< span class = "md-headline" > Last events< / span >
< / md-card-title-text >
< / md-card-title >
< kbn-dis table-height = "600px;" dis-a = "(columns:!(SyscheckFile.path,SyscheckFile.event,SyscheckFile.uname_after,SyscheckFile.gname_after,full_log),index:'ossec-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'location:%20syscheck')),sort:!('@timestamp',desc))"
dis-g="(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-{{timerFilterValue}},mode:quick,to:now))"
dis-filter="location: syscheck AND {{'AgentName:'+_agent.name}}"
infinite-scroll="true">
< / kbn-dis >
< / md-card >
2016-09-02 10:10:10 +00:00
< / div >
2016-09-22 15:24:30 +00:00
2016-09-02 10:10:10 +00:00
< / div >
2016-08-30 19:51:41 +00:00
< / md-content >