mirror of
https://github.com/valitydev/wazuh-kibana-app.git
synced 2024-11-08 02:38:51 +00:00
Merge pull request #64 from wazuh/3.0-dev-agents-tab-visualizations
Replacing all visualizations in the agents tab
This commit is contained in:
commit
35403a9001
@ -1,10 +1,22 @@
|
||||
<md-content ng-if="submenuNavItem == 'audit' && _agent" id="agents-audit" ng-controller="auditController">
|
||||
<md-content ng-if="submenuNavItem == 'audit' && _agent" id="agents-audit" ng-controller="auditController" class="app-container wazuh-column">
|
||||
|
||||
<!--FUCKING RING<div class='uil-ring-css' ng-if="tabView == 'panels'"><div></div></div>-->
|
||||
|
||||
<!-- Kibana search bar -->
|
||||
<kbn-searchbar ng-if="tabView == 'panels'"></kbn-searchbar>
|
||||
<div class='uil-ring-css' ng-if="tabView == 'panels'" ng-show='!hideRing(15)'><div></div></div>
|
||||
<!-- Local nav. -->
|
||||
<div ng-if="!loading" ng-controller="kibanaSearchbar">
|
||||
<kbn-top-nav name="agents_fim" config="topNavMenu">
|
||||
<div data-transclude-slots>
|
||||
<div ng-show="chrome.getVisible()" class="fullWidth" data-transclude-slot="bottomRow">
|
||||
<query-bar query="state.query" app-name="'wazuh'" on-submit="updateQueryAndFetch($query)"></query-bar>
|
||||
</div>
|
||||
</div>
|
||||
</kbn-top-nav>
|
||||
|
||||
<filter-bar ng-show="showFilterBar()" state="state" index-patterns="indexPattern" ng-if="state.query.language === 'lucene'"></filter-bar>
|
||||
</div>
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels' && hideRing(15)">
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels'">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
@ -15,189 +27,157 @@
|
||||
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name" >
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
dis-filter="rule.groups:audit"
|
||||
infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))" dis-filter="rule.groups:audit" infinite-scroll="true"></kbn-disfull>
|
||||
</md-content>
|
||||
|
||||
<div flex ng-show="hideRing(15) && results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<div flex ng-show="results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
<md-content layout="row" layout-align="center stretch" class="metrics-audit">
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="123px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:'New files'),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="rule.groups: audit AND rule.id: 80790 AND agent.name: {{_agent.name ? _agent.name : '*'}}"></kbn-vis>
|
||||
</md-card-content>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 115px;">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content class="wazuh-row metric">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-New-files-metric'" id="Wazuh-App-Agents-Audit-New-files-metric"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card-content class="metric">
|
||||
<kbn-vis vis-height="123px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:'Read files'),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="rule.groups: audit AND rule.id: 80784 AND agent.name: {{_agent.name ? _agent.name : '*'}}"></kbn-vis>
|
||||
</md-card-content>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content class="wazuh-row metric">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Read-files-metric'" id="Wazuh-App-Agents-Audit-Read-files-metric"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card-content class="metric">
|
||||
<kbn-vis vis-height="123px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:'Modified files'),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="rule.groups: audit AND rule.id: 80781 AND agent.name: {{_agent.name ? _agent.name : '*'}}"></kbn-vis>
|
||||
</md-card-content>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content class="wazuh-row metric">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Modified-files-metric'" id="Wazuh-App-Agents-Audit-Modified-files-metric"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card-content class="metric">
|
||||
<kbn-vis vis-height="123px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(customLabel:'Removed files'),schema:metric,type:count)),listeners:(),params:(fontSize:20,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="rule.groups: audit AND rule.id: 80791 AND agent.name: {{_agent.name ? _agent.name : '*'}}"></kbn-vis>
|
||||
</md-card-content>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content class="wazuh-row metric">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Removed-files-metric'" id="Wazuh-App-Agents-Audit-Removed-files-metric"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="60" layout="column" layout-align="center center">
|
||||
<md-card-content style="text-align: center;">
|
||||
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content class="wazuh-row" style="text-align: center;">
|
||||
<div class="ng-binding">Latest alert</div>
|
||||
<kbn-vis-value vis-height="32px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:rule.description,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter="rule.groups: audit"></kbn-vis-value>
|
||||
<kbn-vis class="kbn-vis-value" vis-id="'Wazuh-App-Agents-Audit-Latest-alert'" id="Wazuh-App-Agents-Audit-Latest-alert"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 200px;">
|
||||
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Groups</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Groups'" id="Wazuh-App-Agents-Audit-Groups"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Directories</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Directories'" id="Wazuh-App-Agents-Audit-Groups"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Files</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Files'" id="Wazuh-App-Agents-Audit-Files"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="33">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Groups</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="180px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.groups,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'Audit:%20Rule%20groups',type:pie))"
|
||||
vis-filter="rule.groups: audit">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="33">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Directories</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="180px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.directory.name,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'Audit:%20Directories',type:pie))"
|
||||
vis-filter="rule.groups: audit">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 310px;">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts over time</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Alerts-over-time'" id="Wazuh-App-Agents-Audit-Alerts-over-time"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<md-card flex="33">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Files</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="180px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.file.name,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'Audit:%20Files',type:pie))"
|
||||
vis-filter="rule.groups: audit">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 140px;">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">File read access</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-File-read-access'" id="Wazuh-App-Agents-Audit-File-read-access"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="100">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts over time</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis class="vis-expand-leyend" vis-height="290px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',extended_bounds:(),field:'@timestamp',interval:auto,min_doc_count:1),schema:segment,type:date_histogram),(enabled:!t,id:'3',params:(field:rule.description,order:desc,orderBy:'1',size:10),schema:group,type:terms)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,interpolate:linear,legendPosition:right,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,smoothLines:!t,times:!(),yAxis:()),title:'Audit:%20Alerts%20over%20time',type:area))"
|
||||
vis-filter="rule.groups: audit">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">File write access</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-File-write-access'" id="Wazuh-App-Agents-Audit-File-write-access"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Created files</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Created-files'" id="Wazuh-App-Agents-Audit-Created-files"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-content style="height: 448px" layout="row" layout-align="center stretch">
|
||||
<md-content flex="20" layout="column" layout-align="center stretch">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Removed files</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Removed-files'" id="Wazuh-App-Agents-Audit-Removed-files"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">File read access</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="120px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.file.name,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Audit:%20File%20read%20access',type:pie))"
|
||||
vis-filter="rule.groups: audit AND rule.id: 80784">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 320px;">
|
||||
<md-card flex="40" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Commands</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Commands'" id="Wazuh-App-Agents-Audit-Commands"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">File write access</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="120px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.file.name,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Audit:%20File%20read%20access',type:pie))"
|
||||
vis-filter="rule.groups: audit AND rule.id: 80781">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
<md-content flex="60" layout="column" layout-align="center stretch">
|
||||
<md-card flex="100">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Commands</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="340px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.command,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Audit:%20File%20read%20access',type:pie))"
|
||||
vis-filter="rule.groups: audit">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
<md-content flex="20" layout="column" layout-align="center stretch">
|
||||
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Created files</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="120px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.file.name,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Audit:%20File%20read%20access',type:pie))"
|
||||
vis-filter="rule.groups: audit AND rule.id: 80790">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Removed files</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="120px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'',field:data.audit.file.name,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Audit:%20File%20read%20access',type:pie))"
|
||||
vis-filter="rule.groups: audit AND rule.id: 80791">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
</md-content>
|
||||
|
||||
<md-content layout-align="center stretch">
|
||||
<md-card flex>
|
||||
<md-card flex="60" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Last alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%20audit')),uiState:(spy:(mode:(fill:!f,name:!n)),vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:99999),schema:bucket,type:terms),(enabled:!t,id:'3',params:(customLabel:Event,field:rule.description,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:Command,field:data.audit.exe,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Type,field:data.audit.type,order:desc,orderBy:'1',size:5),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:'Effective user ID',field:data.audit.euid,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
|
||||
vis-filter="rule.groups: audit">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Audit-Last-alerts'" id="Wazuh-App-Agents-Audit-Last-alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
</div>
|
||||
</div>
|
||||
</md-content>
|
||||
</md-content>
|
@ -1,11 +1,31 @@
|
||||
<md-content ng-if="submenuNavItem == 'fim' && _agent" id="agents-fim" ng-controller="fimController">
|
||||
<md-content ng-if="submenuNavItem == 'fim' && _agent" id="agents-fim" ng-controller="fimController" class="app-container wazuh-column">
|
||||
|
||||
<!--<div class='uil-ring-css' ng-if="tabView == 'panels'">
|
||||
<div></div>
|
||||
</div>-->
|
||||
|
||||
<!-- Kibana search bar -->
|
||||
<kbn-searchbar ng-if="tabView == 'panels'"></kbn-searchbar>
|
||||
<div class='uil-ring-css' ng-if="tabView == 'panels'" ng-show='!hideRing(8)'><div></div></div>
|
||||
<!-- Local nav. -->
|
||||
<div ng-if="!loading" ng-controller="kibanaSearchbar">
|
||||
<kbn-top-nav name="agents_fim" config="topNavMenu">
|
||||
<!-- Transcluded elements. -->
|
||||
<div data-transclude-slots>
|
||||
<!-- Title. -->
|
||||
|
||||
<!-- Search. -->
|
||||
<div ng-show="chrome.getVisible()" class="fullWidth" data-transclude-slot="bottomRow">
|
||||
<query-bar query="state.query" app-name="'wazuh'" on-submit="updateQueryAndFetch($query)">
|
||||
</query-bar>
|
||||
</div>
|
||||
</div>
|
||||
</kbn-top-nav>
|
||||
|
||||
<!-- Filters. -->
|
||||
<filter-bar ng-show="showFilterBar()" state="state" index-patterns="indexPattern" ng-if="state.query.language === 'lucene'"></filter-bar>
|
||||
</div>
|
||||
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels' && hideRing(8)">
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels'">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
@ -16,113 +36,104 @@
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="$parent.tabView == 'discover' && agentInfo.name">
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
dis-filter="rule.groups:syscheck "
|
||||
infinite-scroll="true">
|
||||
dis-filter="rule.groups:syscheck " infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
</md-content>
|
||||
|
||||
<!-- View: Panels -->
|
||||
<div flex layout="column" ng-show='hideRing(8) && results && !loading' ng-if="tabView == 'panels' && !load">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
<md-content layout="row">
|
||||
<md-card flex="33">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Users</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:syscheck.uname_after,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%2015%20new%20users2',type:pie))" vis-filter="rule.groups: syscheck">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="33">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Groups</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:syscheck.gname_after,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%2015%20new%20users',type:pie))" vis-filter="rule.groups: syscheck">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="33">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Permissions</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:syscheck.perm_after,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'FIM%20Top%20permissions',type:pie))" vis-filter="rule.groups: syscheck">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<div flex ng-show='results && !loading' ng-if="tabView == 'panels' && !load" class="wazuh-column">
|
||||
|
||||
</md-content>
|
||||
<md-content layout="row">
|
||||
<md-card flex>
|
||||
<md-card-title>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 174px;">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title><md-card-title-text>
|
||||
<span class="md-headline">Users</span>
|
||||
</md-card-title-text></md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Users'" id="Wazuh-App-Agents-FIM-Users">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title><md-card-title-text>
|
||||
<span class="md-headline">Groups</span>
|
||||
</md-card-title-text></md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Groups'" id="Wazuh-App-Agents-FIM-Groups">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title><md-card-title-text>
|
||||
<span class="md-headline">Permissions</span>
|
||||
</md-card-title-text></md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Permissions'" id="Wazuh-App-Agents-FIM-Permissions">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 190px;">
|
||||
<md-content layout="row" class="wazuh-row">
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Events</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<kbn-vis vis-height="160px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',extended_bounds:(),field:'@timestamp',interval:'auto',min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))" vis-filter="rule.groups: syscheck">
|
||||
</kbn-vis>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<md-content layout="row">
|
||||
<md-card flex="33">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Events'" id="Wazuh-App-Agents-FIM-Events"></kbn-vis>
|
||||
</md-card>
|
||||
</md-content>
|
||||
</div>
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 174px;">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Files added</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'New%20Visualization',type:pie))"
|
||||
vis-filter="rule.id: 554 AND NOT location: syscheck-registry">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Files-added'" id="Wazuh-App-Agents-FIM-Files-added"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="33">
|
||||
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Files modified</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'FIM%20Top%2010%20Changed',type:pie))"
|
||||
vis-filter="(rule.id: 550 OR rule.id: 551 OR rule.id: 552 OR rule.id: 555) AND NOT location: syscheck-registry">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Files-modified'" id="Wazuh-App-Agents-FIM-Files-modified"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="33">
|
||||
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Files deleted</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:syscheck.path,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,shareYAxis:!t),title:'New%20Visualization',type:pie))"
|
||||
vis-filter="rule.id: 553 AND NOT location: syscheck-registry">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Files-deleted'" id="Wazuh-App-Agents-FIM-Files-deleted"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<div layout="row" layout-align="space-between stretch">
|
||||
<md-card flex="100">
|
||||
</div>
|
||||
|
||||
<div layout="row" layout-align="space-between stretch" class="wazuh-row" style="height: 470px">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts summary</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:Agent,field:agent.name,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:File,field:syscheck.path,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:Event,field:syscheck.event,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Description,field:rule.description,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
|
||||
vis-filter="rule.groups: syscheck">
|
||||
</kbn-vis>
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-FIM-Alerts-summary'" id="Wazuh-App-Agents-FIM-Alerts-summary"></kbn-vis>
|
||||
</md-card>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</md-content>
|
||||
</md-content>
|
@ -1,11 +1,31 @@
|
||||
<md-content ng-if="submenuNavItem == 'oscap' && _agent" id="agents-oscap" ng-controller="oscapController">
|
||||
<md-content ng-if="submenuNavItem == 'oscap' && _agent" id="agents-oscap" ng-controller="oscapController" class="app-container wazuh-column">
|
||||
|
||||
<!--<div class='uil-ring-css' ng-if="tabView == 'panels'">
|
||||
<div></div>
|
||||
</div>-->
|
||||
|
||||
<!-- Kibana search bar -->
|
||||
<kbn-searchbar ng-if="tabView == 'panels'"></kbn-searchbar>
|
||||
<div class='uil-ring-css' ng-if="tabView == 'panels'" ng-show='!hideRing(13)'><div></div></div>
|
||||
<!-- Local nav. -->
|
||||
<div ng-if="!loading" ng-controller="kibanaSearchbar">
|
||||
<kbn-top-nav name="agents_fim" config="topNavMenu">
|
||||
<!-- Transcluded elements. -->
|
||||
<div data-transclude-slots>
|
||||
<!-- Title. -->
|
||||
|
||||
<!-- Search. -->
|
||||
<div ng-show="chrome.getVisible()" class="fullWidth" data-transclude-slot="bottomRow">
|
||||
<query-bar query="state.query" app-name="'wazuh'" on-submit="updateQueryAndFetch($query)">
|
||||
</query-bar>
|
||||
</div>
|
||||
</div>
|
||||
</kbn-top-nav>
|
||||
|
||||
<!-- Filters. -->
|
||||
<filter-bar ng-show="showFilterBar()" state="state" index-patterns="indexPattern" ng-if="state.query.language === 'lucene'"></filter-bar>
|
||||
</div>
|
||||
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels' && hideRing(13)">
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels'">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
@ -17,160 +37,148 @@
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name">
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
dis-filter="rule.groups:oscap"
|
||||
infinite-scroll="true">
|
||||
dis-filter="rule.groups:oscap" infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
</md-content>
|
||||
|
||||
<div flex ng-show="hideRing(13) && results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="20" layout="column">
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="110px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(field:data.oscap.scan.score,customLabel:'Higher score'),schema:metric,type:max)),listeners:(),params:(fontSize:19,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="agent.name: {{_agent.name ? _agent.name : '*'}}"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="20" layout="column">
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="110px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(field:data.oscap.scan.score,customLabel:'Lower score'),schema:metric,type:min)),listeners:(),params:(fontSize:19,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="agent.name: {{_agent.name ? _agent.name : '*'}}">
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="20" layout="column">
|
||||
<md-card-content class="metric">
|
||||
<div class="ng-binding">Last score</div>
|
||||
<kbn-vis-value style="margin-top: 6px" vis-height="37px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:data.oscap.scan.score,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter=""></kbn-vis-value>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="40" layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
<div class="ng-binding">Last scan profile</div>
|
||||
<kbn-vis-value vis-height="37px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:data.oscap.scan.profile.title,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter="data.oscap.check.result: fail AND rule.groups: oscap"></kbn-vis-value>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<div flex ng-show="results && !loading" ng-if="tabView == 'panels' && !load" class="wazuh-column">
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 115px;">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content flex class="wazuh-row metric">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Higher-score-metric'" id="Wazuh-App-Agents-OSCAP-Higher-score-metric"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content flex class="wazuh-row metric">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Lower-score-metric'" id="Wazuh-App-Agents-OSCAP-Lower-score-metric"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content flex class="wazuh-row">
|
||||
<div class="ng-binding">Last score</div>
|
||||
<kbn-vis class="kbn-vis-value" vis-id="'Wazuh-App-Agents-OSCAP-Last-score'" id="Wazuh-App-Agents-OSCAP-Last-score"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content flex class="wazuh-row">
|
||||
<div class="ng-binding">Last scan profile</div>
|
||||
<kbn-vis class="kbn-vis-value" vis-id="'Wazuh-App-Agents-OSCAP-Last-scan-profile'" id="Wazuh-App-Agents-OSCAP-Last-scan-profile"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="25">
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 175px;">
|
||||
<md-content layout="row" class="wazuh-column">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Scans</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.scan.id,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Agents',type:pie))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Scans'" id="Wazuh-App-Agents-OSCAP-Scans"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="25">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Profiles</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:data.oscap.scan.profile.title,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Profiles',type:pie))"
|
||||
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Profiles'" id="Wazuh-App-Agents-OSCAP-Profiles"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="25">
|
||||
</md-content>
|
||||
</div>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 175px;">
|
||||
<md-content layout="row" class="wazuh-column">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Content</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.scan.content,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Content',type:pie))"
|
||||
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Content'" id="Wazuh-App-Agents-OSCAP-Content"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="25">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Severity</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.severity,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Content',type:pie))"
|
||||
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Severity'" id="Wazuh-App-Agents-OSCAP-Severity"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
<md-content layout="row" layout-align="start stretch">
|
||||
<md-card flex>
|
||||
</md-content>
|
||||
</div>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 190px;">
|
||||
<md-content layout="row" layout-align="start stretch" class="wazuh-row">
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Daily scans evolution</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="160px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:oscap%20AND%20agent.name:localCentos')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',customLabel:'Daily scans',extended_bounds:(),field:'@timestamp',interval:d,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,legendPosition:right,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))"
|
||||
vis-filter="rule.groups: oscap AND data.oscap.check.result:fail">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Daily-scans-evolution'" id="Wazuh-App-Agents-OSCAP-Daily-scans-evolution"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
</div>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 320px;">
|
||||
<md-content layout="row" layout-align="center stretch" class="wazuh-row">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 10 - Alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Top-10-Alerts'" id="Wazuh-App-Agents-OSCAP-Top-10-Alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 10 - High risk alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Top-10-High-risk-alerts'" id="Wazuh-App-Agents-OSCAP-Top-10-High-risk-alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 10 - Alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis class="vis-expand-leyend" vis-height="300px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.title,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Top%2020%20failed%20checks',type:pie))"
|
||||
vis-filter="data.oscap.check.result: fail AND rule.groups:oscap AND rule.groups: oscap-result AND data.oscap.check.result:fail">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 10 - High risk alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis class="vis-expand-leyend" vis-height="300px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.title,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Top%2020%20failed%20checks',type:pie))"
|
||||
vis-filter="data.oscap.check.severity: high AND data.oscap.check.result: fail AND rule.groups:oscap AND rule.groups: oscap-result AND data.oscap.check.result:fail">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
</md-content>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="100" layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
<kbn-vis-value vis-height="44px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:data.oscap.check.title,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter="data.oscap.check.result: fail AND rule.groups:oscap">
|
||||
</kbn-vis-value>
|
||||
<div class="ng-binding">Top alert</div>
|
||||
</md-content>
|
||||
</div>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 115px;">
|
||||
<md-card class="wazuh-row">
|
||||
<md-card-content style="text-align: center;" class="wazuh-row">
|
||||
<div class="ng-binding">Top alert</div>
|
||||
<kbn-vis class="kbn-vis-value" vis-id="'Wazuh-App-Agents-OSCAP-Top-alert'" id="Wazuh-App-Agents-OSCAP-Top-alert"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
|
||||
<md-content layout-align="center stretch">
|
||||
<md-card flex>
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Last alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:99999),schema:bucket,type:terms),(enabled:!t,id:'3',params:(customLabel:Title,field:data.oscap.check.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:Profile,field:data.oscap.scan.profile.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:'Scan ID',field:data.oscap.scan.id,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Content,field:data.oscap.scan.content,order:desc,orderBy:'1',size:5),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
|
||||
vis-filter="data.oscap.check.result: fail AND rule.groups: oscap">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
</div>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 470px;">
|
||||
<md-content layout-align="center stretch" class="wazuh-row">
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Last alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-OSCAP-Last-alerts'" id="Wazuh-App-Agents-OSCAP-Last-alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
</div>
|
||||
</div>
|
||||
</md-content>
|
||||
</md-content>
|
@ -1,22 +1,45 @@
|
||||
<md-content ng-if="submenuNavItem == 'overview' && agentInfo" ng-controller="agentsOverviewController">
|
||||
<md-content ng-if="submenuNavItem == 'overview' && agentInfo" ng-controller="agentsOverviewController" class="app-container wazuh-column">
|
||||
|
||||
<!--<div class='uil-ring-css' ng-if="tabView == 'panels'">
|
||||
<div></div>
|
||||
</div>-->
|
||||
|
||||
<!-- Kibana search bar -->
|
||||
<kbn-searchbar ng-if="tabView == 'panels'"></kbn-searchbar>
|
||||
<div class='uil-ring-css' ng-if="tabView == 'panels'" ng-show='!hideRing(7)'><div></div></div>
|
||||
<div ng-show='hideRing(7) && !loading' ng-if="tabView == 'panels'">
|
||||
<!-- Local nav. -->
|
||||
<div ng-if="!loading" ng-controller="kibanaSearchbar">
|
||||
<kbn-top-nav name="agents_fim" config="topNavMenu">
|
||||
<!-- Transcluded elements. -->
|
||||
<div data-transclude-slots>
|
||||
<!-- Title. -->
|
||||
|
||||
<!-- Search. -->
|
||||
<div ng-show="chrome.getVisible()" class="fullWidth" data-transclude-slot="bottomRow">
|
||||
<query-bar query="state.query" app-name="'wazuh'" on-submit="updateQueryAndFetch($query)">
|
||||
</query-bar>
|
||||
</div>
|
||||
</div>
|
||||
</kbn-top-nav>
|
||||
|
||||
<!-- Filters. -->
|
||||
<filter-bar ng-show="showFilterBar()" state="state" index-patterns="indexPattern" ng-if="state.query.language === 'lucene'"></filter-bar>
|
||||
</div>
|
||||
|
||||
|
||||
<div ng-show='!loading' ng-if="tabView == 'panels'">
|
||||
<md-content layout="row">
|
||||
<md-card flex layout="column">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
<div class="metric-value ng-binding" style="font-size: 14pt;">{{agentInfo.name}}</div>
|
||||
<div class="ng-binding">Name</div>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
<div class="metric-value ng-binding" style="font-size: 14pt;">{{agentInfo.ip}}</div>
|
||||
<div class="ng-binding">IP Address</div>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card flex="10" layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
<div class="metric-value ng-binding" style="font-size: 14pt;">{{ agentInfo.version | limitTo: 12 }}{{agentInfo.version.length > 12 ? '...' : ''}}</div>
|
||||
<md-tooltip md-direction="bottom">{{ agentInfo.version }}</md-tooltip>
|
||||
@ -48,9 +71,9 @@
|
||||
<md-card-content style="text-align: center;">
|
||||
<div class="metric-value ng-binding" style="font-size: 14pt;">{{agentInfo.syscheck.end}}</div>
|
||||
<md-tooltip md-direction="bottom">
|
||||
Start time: {{ agentInfo.syscheck.start }} <br>
|
||||
End time: {{ agentInfo.syscheck.end }} <br>
|
||||
Duration time: {{ agentInfo.syscheck.duration }} minutes
|
||||
Start time: {{ agentInfo.syscheck.start }}
|
||||
<br> End time: {{ agentInfo.syscheck.end }}
|
||||
<br> Duration time: {{ agentInfo.syscheck.duration }} minutes
|
||||
</md-tooltip>
|
||||
<div class="ng-binding">Last syscheck scan</div>
|
||||
</md-card-content>
|
||||
@ -59,9 +82,9 @@
|
||||
<md-card-content style="text-align: center;">
|
||||
<div class="metric-value ng-binding" style="font-size: 14pt;">{{agentInfo.rootcheck.end}}</div>
|
||||
<md-tooltip md-direction="bottom">
|
||||
Start time: {{ agentInfo.rootcheck.start }} <br>
|
||||
End time: {{ agentInfo.rootcheck.end }} <br>
|
||||
Duration time: {{ agentInfo.rootcheck.duration }} minutes
|
||||
Start time: {{ agentInfo.rootcheck.start }}
|
||||
<br> End time: {{ agentInfo.rootcheck.end }}
|
||||
<br> Duration time: {{ agentInfo.rootcheck.duration }} minutes
|
||||
</md-tooltip>
|
||||
<div class="ng-binding">Last rootcheck scan</div>
|
||||
</md-card-content>
|
||||
@ -70,7 +93,7 @@
|
||||
</div>
|
||||
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels' && hideRing(7)">
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels'">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
@ -79,104 +102,95 @@
|
||||
</md-content>
|
||||
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name" >
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name">
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
infinite-scroll="true">
|
||||
infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
</md-content>
|
||||
|
||||
<!-- View: Panels -->
|
||||
<div ng-show='hideRing(7) && results' ng-if="tabView == 'panels' && !loading">
|
||||
<md-content layout="row">
|
||||
<md-card flex="33">
|
||||
<div ng-show='results' ng-if="tabView == 'panels' && !loading">
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 174px;">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.description,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'Top 5',type:pie))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Top-5-alerts'" id="Wazuh-App-Agents-Overview-Top-5-alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="33">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 groups</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.groups,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'Top groups',type:pie))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Top-5-groups'" id="Wazuh-App-Agents-Overview-Top-5-groups"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="33">
|
||||
</div>
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 170px;">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 PCI DSS Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.pci_dss,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'Top pci',type:pie))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Top-5-PCI-DSS-Requirements'" id="Wazuh-App-Agents-Overview-Top-5-PCI-DSS-Requirements"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<md-content layout="row" layout-align="start stretch">
|
||||
<md-card flex class="visBox-alert-level-evolution">
|
||||
<md-card flex="50" class="wazuh-row visBox-alert-level-evolution">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alert level evolution</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="150px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:rule.level,order:desc,orderBy:'1',size:10),schema:group,type:terms),(enabled:!t,id:'2',params:(customInterval:'1h',extended_bounds:(),field:'@timestamp',interval:h,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,drawLinesBetweenPoints:!t,interpolate:cardinal,legendPosition:right,radiusRatio:9,scale:linear,setYExtents:!f,shareYAxis:!t,showCircles:!t,smoothLines:!f,times:!(),yAxis:()),title:'Alert%20level%20evolution',type:line))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Alert-level-evolution'" id="Wazuh-App-Agents-Overview-Alert-level-evolution"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
|
||||
<md-card flex="60">
|
||||
</div>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 170px;">
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="150px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'1h',customLabel:'Agent alerts',extended_bounds:(),field:'@timestamp',interval:h,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'Agentbalerts last 24 days',type:histogram))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Alerts'" id="Wazuh-App-Agents-Overview-Alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<md-content layout="row">
|
||||
<md-card flex="60">
|
||||
</div>
|
||||
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 480px;">
|
||||
<md-card flex="60" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts summary</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="460px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'Rule ID',field:rule.id,order:desc,orderBy:'1',size:99999),schema:bucket,type:terms),(enabled:!t,id:'3',params:(customLabel:Description,field:rule.description,order:desc,orderBy:'1',size:1),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:Level,field:rule.level,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Alerts-summary'" id="Wazuh-App-Agents-Overview-Alerts-summary"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="40">
|
||||
<md-card flex="40" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Groups summary</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:1,direction:desc)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:Group,field:rule.groups,order:desc,orderBy:'1',size:99999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:5,direction:desc),totalFunc:sum),title:'Groups',type:table))"
|
||||
vis-filter="">
|
||||
</kbn-vis>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Overview-Groups-summary'" id="Wazuh-App-Agents-Overview-Groups-summary"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
</div>
|
||||
</div>
|
||||
</md-content>
|
||||
</md-content>
|
@ -1,11 +1,32 @@
|
||||
<md-content ng-if="submenuNavItem == 'pci' && _agent" id="agents-pci" ng-controller="PCIController">
|
||||
<md-content ng-if="submenuNavItem == 'pci' && _agent" id="agents-pci" ng-controller="PCIController" class="app-container wazuh-column">
|
||||
|
||||
<!--<div class='uil-ring-css' ng-if="tabView == 'panels'">
|
||||
<div></div>
|
||||
</div>-->
|
||||
|
||||
<!-- Kibana search bar -->
|
||||
<kbn-searchbar ng-if="tabView == 'panels'"></kbn-searchbar>
|
||||
<div class='uil-ring-css' ng-if="tabView == 'panels'" ng-show='!hideRing(3)'><div></div></div>
|
||||
<!-- Local nav. -->
|
||||
<div ng-if="!loading" ng-controller="kibanaSearchbar">
|
||||
<kbn-top-nav name="agents_fim" config="topNavMenu">
|
||||
<!-- Transcluded elements. -->
|
||||
<div data-transclude-slots>
|
||||
<!-- Title. -->
|
||||
|
||||
<!-- Search. -->
|
||||
<div ng-show="chrome.getVisible()" class="fullWidth" data-transclude-slot="bottomRow">
|
||||
<query-bar query="state.query" app-name="'wazuh'" on-submit="updateQueryAndFetch($query)">
|
||||
</query-bar>
|
||||
</div>
|
||||
</div>
|
||||
</kbn-top-nav>
|
||||
|
||||
<!-- Filters. -->
|
||||
<filter-bar ng-show="showFilterBar()" state="state" index-patterns="indexPattern" ng-if="state.query.language === 'lucene'"></filter-bar>
|
||||
</div>
|
||||
|
||||
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels' && hideRing(3)">
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels'">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
@ -17,67 +38,61 @@
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name">
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
dis-filter="_exists_:rule.pci_dss "
|
||||
infinite-scroll="true">
|
||||
dis-filter="_exists_:rule.pci_dss " infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
</md-content>
|
||||
|
||||
<div flex ng-show="hideRing(3) && results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
<div flex ng-show="results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex>
|
||||
<md-tabs md-selected="selectedIndex" md-border-bottom md-dynamic-height id="pciReq_tab">
|
||||
<md-tab ng-repeat="tab in tabs" ng-disabled="tab.disabled" label="{{tab.title}}">
|
||||
<md-content style="background-color: white;" class="md-padding">
|
||||
<h1 class="md-display-2 wazuh-h1" style="line-height: 40px; margin: 0;">PCI DSS Requirement: {{tab.title}}</h1>
|
||||
<div ng-bind-html="tab.content"></div>
|
||||
</md-content>
|
||||
</md-tab>
|
||||
</md-tabs>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<md-card flex>
|
||||
<md-tabs md-selected="selectedIndex" md-border-bottom md-dynamic-height id="pciReq_tab">
|
||||
<md-tab ng-repeat="tab in tabs" ng-disabled="tab.disabled" label="{{tab.title}}">
|
||||
<md-content style="background-color: white;" class="md-padding">
|
||||
<h1 class="md-display-2 wazuh-h1" style="line-height: 40px; margin: 0;">PCI DSS Requirement: {{tab.title}}</h1>
|
||||
<div ng-bind-html="tab.content"></div>
|
||||
</md-content>
|
||||
</md-tab>
|
||||
</md-tabs>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
<md-content layout="row" layout-align="center stretch">
|
||||
<md-card flex="70">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="235px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:rule.pci_dss,order:desc,orderBy:'1',size:10),schema:group,type:terms),(enabled:!t,id:'2',params:(customLabel:'PCI DSS Requirements',field:rule.pci_dss,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,legendPosition:right,mode:grouped,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'PCI%20Requirements%20%2F%20Agent',type:histogram))"
|
||||
vis-filter="_exists_:rule.pci_dss">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="30">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Groups</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="235px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:rule.groups,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Groups',type:pie))"
|
||||
vis-filter="_exists_:rule.pci_dss"">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 255px;">
|
||||
<md-card flex="70" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-PCI-Requirements'" id="Wazuh-App-Agents-PCI-Requirements"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="30" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Groups</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-PCI-Groups'" id="Wazuh-App-Agents-PCI-Groups"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<md-content layout-align="center stretch">
|
||||
<md-card flex>
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Last alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:3,direction:desc)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'4',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:99999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:Requirement,field:rule.pci_dss,order:desc,orderBy:'1',size:99999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:'Rule description',field:rule.description,order:desc,orderBy:'1',size:99999999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'Requirements%20by%20agent',type:table))"
|
||||
vis-filter="_exists_:rule.pci_dss"">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 470px;">
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline ">Last alerts</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-PCI-Last-alerts'" id="Wazuh-App-Agents-PCI-Last-alerts"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</md-content>
|
@ -1,82 +1,94 @@
|
||||
<md-content ng-if="submenuNavItem == 'policy_monitoring' && _agent" id="agents-pm" ng-controller="pmController">
|
||||
|
||||
<!-- Kibana search bar -->
|
||||
<kbn-searchbar ng-if="tabView == 'panels'"></kbn-searchbar>
|
||||
<div class='uil-ring-css' ng-if="tabView == 'panels'" ng-show='!hideRing(4)'><div></div></div>
|
||||
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels' && hideRing(4)">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<md-content ng-if="submenuNavItem == 'policy_monitoring' && _agent" id="agents-pm" ng-controller="pmController" class="app-container wazuh-column">
|
||||
|
||||
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name" >
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
dis-filter="rule.groups:rootcheck"
|
||||
infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
</md-content>
|
||||
<!--<div class='uil-ring-css' ng-if="tabView == 'panels'">
|
||||
<div></div>
|
||||
</div>-->
|
||||
|
||||
<div flex ng-show="hideRing(4) && results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
<md-content layout="row">
|
||||
<md-card flex="50">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts over time</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="220px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',extended_bounds:(),field:'@timestamp',interval:auto,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))"
|
||||
vis-filter="rule.groups: rootcheck">
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="25">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 CIS Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="220px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.cis,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'New%20Visualization',type:pie))"
|
||||
vis-filter="rule.groups: rootcheck"
|
||||
>
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="25">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 PCI DSS Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content>
|
||||
<kbn-vis vis-height="220px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:%22rootcheck%22')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:rule.pci_dss,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,shareYAxis:!t),title:'PM%20Top%2010%20PCI%20DSS%20Requirements',type:pie))"
|
||||
vis-filter="rule.groups: rootcheck"
|
||||
>
|
||||
</kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
<div layout="row" layout-align="space-between stretch">
|
||||
<md-card flex="100">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts summary</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:3,direction:desc)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'3',params:(customLabel:'Rule description',field:rule.description,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:Control,field:data.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
|
||||
vis-filter="rule.groups: rootcheck">
|
||||
</kbn-vis>
|
||||
<!-- Kibana search bar -->
|
||||
<!-- Local nav. -->
|
||||
<div ng-if="!loading" ng-controller="kibanaSearchbar">
|
||||
<kbn-top-nav name="agents_fim" config="topNavMenu">
|
||||
<!-- Transcluded elements. -->
|
||||
<div data-transclude-slots>
|
||||
<!-- Title. -->
|
||||
|
||||
</md-card>
|
||||
<!-- Search. -->
|
||||
<div ng-show="chrome.getVisible()" class="fullWidth" data-transclude-slot="bottomRow">
|
||||
<query-bar query="state.query" app-name="'wazuh'" on-submit="updateQueryAndFetch($query)">
|
||||
</query-bar>
|
||||
</div>
|
||||
</div>
|
||||
</kbn-top-nav>
|
||||
|
||||
</div>
|
||||
<!-- Filters. -->
|
||||
<filter-bar ng-show="showFilterBar()" state="state" index-patterns="indexPattern" ng-if="state.query.language === 'lucene'"></filter-bar>
|
||||
</div>
|
||||
</md-content>
|
||||
|
||||
<!-- No results message -->
|
||||
<md-content flex layout="row" layout-align="start start" ng-show="!results && !loading" ng-if="tabView == 'panels'">
|
||||
<md-card flex layout="column">
|
||||
<md-card-content style="text-align: center;">
|
||||
No results for selected time interval
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</md-content>
|
||||
|
||||
|
||||
<!-- View: Discover -->
|
||||
<md-content style="background-color: white" flex layout="column" layout-align="start space-around" ng-if="tabView == 'discover' && agentInfo.name">
|
||||
<kbn-disfull table-height="1000px;" dis-a="(columns:!(_source),filters:!(),index:'wazuh-alerts-*',interval:auto,query:(query_string:(analyze_wildcard:!t,query:'*')),sort:!('@timestamp',desc))"
|
||||
dis-filter="rule.groups:rootcheck" infinite-scroll="true">
|
||||
</kbn-disfull>
|
||||
</md-content>
|
||||
|
||||
<div flex ng-show="results && !loading" ng-if="tabView == 'panels' && !load" layout="column">
|
||||
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 240px;">
|
||||
<md-card flex="50" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts over time</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-PM-Alerts-over-time'" id="Wazuh-App-Agents-PM-Alerts-over-time"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="25" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 CIS Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Top-5-CIS-Requirements'" id="Wazuh-App-Agents-PM-Top-5-CIS-Requirements"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
<md-card flex="25" class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Top 5 PCI DSS Requirements</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Top-5-PCI-DSS-Requirements'" id="Wazuh-App-Agents-PM-Top-5-PCI-DSS-Requirements"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
|
||||
<div layout="row" layout-align="center stretch" class="wazuh-row" style="height: 470px;">
|
||||
<md-card flex class="wazuh-row">
|
||||
<md-card-title>
|
||||
<md-card-title-text>
|
||||
<span class="md-headline">Alerts summary</span>
|
||||
</md-card-title-text>
|
||||
</md-card-title>
|
||||
<md-card-content class="wazuh-row">
|
||||
<kbn-vis vis-id="'Wazuh-App-Agents-Alerts-summary'" id="Wazuh-App-Agents-PM-Alerts-summary"></kbn-vis>
|
||||
</md-card-content>
|
||||
</md-card>
|
||||
</div>
|
||||
</div>
|
||||
</md-content>
|
Loading…
Reference in New Issue
Block a user