|
|
|
@ -3,153 +3,59 @@
|
|
|
|
|
<md-progress-linear class="md-accent" md-mode="indeterminate" ng-show="load"></md-progress-linear>
|
|
|
|
|
<kbn-searchbar></kbn-searchbar>
|
|
|
|
|
<md-content layout="row" layout-align="center stretch">
|
|
|
|
|
<md-card flex="20" layout="column">
|
|
|
|
|
<md-card-content style="text-align: center;">
|
|
|
|
|
<kbn-vis vis-height="70px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(field:oscap.scan.score,customLabel:'Higher score'),schema:metric,type:max)),listeners:(),params:(fontSize:19,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="agent.name: {{_agent.name}}"></kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
<md-card flex="20" layout="column">
|
|
|
|
|
<md-card-content style="text-align: center;">
|
|
|
|
|
<kbn-vis vis-height="70px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(field:oscap.scan.score,customLabel:'Lower score'),schema:metric,type:min)),listeners:(),params:(fontSize:19,handleNoResults:!t),title:'New%20Visualization',type:metric))" vis-filter="agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
<md-card flex="20" layout="column">
|
|
|
|
|
<md-card-content style="text-align: center; margin-top: 6px; ">
|
|
|
|
|
<kbn-vis-value style="margin-top: 6px" vis-height="37px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:oscap.scan.score,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter="agent.name: {{_agent.name}}"></kbn-vis-value>
|
|
|
|
|
<div class="ng-binding">Last score</div>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
<md-card flex="40" layout="column">
|
|
|
|
|
<md-card-content style="text-align: center;">
|
|
|
|
|
<kbn-vis-value vis-height="37px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(field:'@timestamp'),schema:metric,type:max),(enabled:!t,id:'2',params:(field:oscap.scan.profile.title,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter="oscap.check.result: fail AND rule.groups: oscap AND agent.name: {{_agent.name}}"></kbn-vis-value>
|
|
|
|
|
<div class="ng-binding">Last scan profile</div>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<md-content layout="row" layout-align="center stretch">
|
|
|
|
|
<md-card flex="25">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Scans</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:oscap.scan.id,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Agents',type:pie))"
|
|
|
|
|
vis-filter="agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
<md-card flex="25">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Profiles</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:oscap.scan.profile.title,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Profiles',type:pie))"
|
|
|
|
|
vis-filter="oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
<md-card flex="25">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Content</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:oscap.scan.content,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Content',type:pie))"
|
|
|
|
|
vis-filter="oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
|
|
|
|
|
<md-card flex="25">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Severity</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="154px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:oscap.check.severity,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Content',type:pie))"
|
|
|
|
|
vis-filter="oscap.check.result: fail AND rule.groups:oscap AND NOT rule.groups: syslog AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
<md-content layout="row" layout-align="center stretch">
|
|
|
|
|
<md-card flex="100">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Daily scans evolution</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="160px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'rule.groups:oscap%20AND%20agent.name:localCentos')),uiState:(vis:(legendOpen:!f)),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customInterval:'2h',customLabel:'Daily scans',extended_bounds:(),field:'@timestamp',interval:d,min_doc_count:1),schema:segment,type:date_histogram)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,legendPosition:right,mode:stacked,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))"
|
|
|
|
|
vis-filter="rule.groups: oscap AND oscap.check.result:fail AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<md-content layout="row" layout-align="center stretch">
|
|
|
|
|
<md-card flex="50">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Top 10 - Alerts</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis class="vis-expand-leyend" vis-height="300px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:oscap.check.title,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Top%2020%20failed%20checks',type:pie))"
|
|
|
|
|
vis-filter="oscap.check.result: fail AND rule.groups:oscap AND rule.groups: oscap-result AND oscap.check.result:fail AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
|
|
|
|
|
<md-card flex="50">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Top 10 - High risk alerts</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis class="vis-expand-leyend" vis-height="300px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:oscap.check.title,order:desc,orderBy:'1',size:10),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!f,legendPosition:right,shareYAxis:!t),title:'OSCAP%20Top%2020%20failed%20checks',type:pie))"
|
|
|
|
|
vis-filter="oscap.check.severity: high AND oscap.check.result: fail AND rule.groups:oscap AND rule.groups: oscap-result AND oscap.check.result:fail AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
<md-content layout="row" layout-align="center stretch" >
|
|
|
|
|
<md-card flex="100" layout="column">
|
|
|
|
|
<md-card-content style="text-align: center;">
|
|
|
|
|
<kbn-vis-value vis-height="44px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(field:oscap.check.title,order:desc,orderBy:'1',size:1),schema:bucket,type:terms)),listeners:(),params:(perPage:1,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))" vis-filter="oscap.check.result: fail AND rule.groups:oscap AND agent.name: {{_agent.name}}">
|
|
|
|
|
</kbn-vis-value>
|
|
|
|
|
<div class="ng-binding">Top alert</div>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<md-content layout-align="center stretch">
|
|
|
|
|
<md-card flex>
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Last alerts</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:!n,direction:!n)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'2',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:99999),schema:bucket,type:terms),(enabled:!t,id:'3',params:(customLabel:Title,field:oscap.check.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'4',params:(customLabel:Profile,field:oscap.scan.profile.title,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:'Scan ID',field:oscap.scan.id,order:desc,orderBy:'1',size:999999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:Content,field:oscap.scan.content,order:desc,orderBy:'1',size:5),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'New%20Visualization',type:table))"
|
|
|
|
|
vis-filter='oscap.check.result: fail AND rule.groups: oscap AND agent.name: {{_agent.name}}'>
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
<md-card flex>
|
|
|
|
|
<md-tabs md-selected="selectedIndex" md-border-bottom md-dynamic-height id="pciReq_tab">
|
|
|
|
|
<md-tab ng-repeat="tab in tabs" ng-disabled="tab.disabled" label="{{tab.title}}">
|
|
|
|
|
<md-content style="background-color: white;" class="md-padding">
|
|
|
|
|
<h1 class="md-display-2" style="line-height: 40px; margin: 0;">PCI DSS Requirement: {{tab.title}}</h1>
|
|
|
|
|
<div ng-bind-html="tab.content"></div>
|
|
|
|
|
</md-content>
|
|
|
|
|
</md-tab>
|
|
|
|
|
</md-tabs>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
<md-content layout="row" layout-align="center stretch">
|
|
|
|
|
<md-card flex="70">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Requirements</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="188px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:rule.pci_dss,order:desc,orderBy:'1',size:10),schema:group,type:terms)),listeners:(),params:(addLegend:!t,addTimeMarker:!f,addTooltip:!t,defaultYExtents:!f,legendPosition:bottom,mode:grouped,orderBucketsBySum:!f,scale:linear,setYExtents:!f,shareYAxis:!t,times:!(),yAxis:()),title:'New%20Visualization',type:histogram))"
|
|
|
|
|
vis-filter="_exists_:rule.pci_dss AND agent.name: {{_agent.name}}"">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
<md-card flex="30">
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Groups</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="188px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'3',params:(field:rule.groups,order:desc,orderBy:'1',size:5),schema:segment,type:terms)),listeners:(),params:(addLegend:!t,addTooltip:!t,isDonut:!t,legendPosition:right,shareYAxis:!t),title:'Groups',type:pie))"
|
|
|
|
|
vis-filter="_exists_:rule.pci_dss AND agent.name: {{_agent.name}}"">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
<md-content layout-align="center stretch">
|
|
|
|
|
<md-card flex>
|
|
|
|
|
<md-card-title>
|
|
|
|
|
<md-card-title-text>
|
|
|
|
|
<span class="md-headline">Last alerts</span>
|
|
|
|
|
</md-card-title-text>
|
|
|
|
|
</md-card-title>
|
|
|
|
|
<md-card-content>
|
|
|
|
|
<kbn-vis vis-height="450px" vis-index-pattern="wazuh-alerts-*" vis-a="(filters:!(),linked:!f,query:(query_string:(analyze_wildcard:!t,query:'*')),uiState:(vis:(params:(sort:(columnIndex:3,direction:desc)))),vis:(aggs:!((enabled:!t,id:'1',params:(),schema:metric,type:count),(enabled:!t,id:'4',params:(customLabel:'Agent name',field:agent.name,order:desc,orderBy:'1',size:99999999),schema:bucket,type:terms),(enabled:!t,id:'5',params:(customLabel:Requirement,field:rule.pci_dss,order:desc,orderBy:'1',size:99999999),schema:bucket,type:terms),(enabled:!t,id:'6',params:(customLabel:'Rule description',field:rule.description,order:desc,orderBy:'1',size:99999999),schema:bucket,type:terms)),listeners:(),params:(perPage:10,showMeticsAtAllLevels:!f,showPartialRows:!f,showTotal:!f,sort:(columnIndex:!n,direction:!n),totalFunc:sum),title:'Requirements%20by%20agent',type:table))"
|
|
|
|
|
vis-filter="_exists_:rule.pci_dss AND agent.name: {{_agent.name}}"">
|
|
|
|
|
</kbn-vis>
|
|
|
|
|
</md-card-content>
|
|
|
|
|
</md-card>
|
|
|
|
|
</md-content>
|
|
|
|
|
|
|
|
|
|
</div>
|
|
|
|
|
</md-content>
|
|
|
|
|