mirror of
https://github.com/valitydev/wazuh-kibana-app.git
synced 2024-11-06 18:05:20 +00:00
Fixed regex from visualizations
This commit is contained in:
parent
76d26555ff
commit
b1e9d2725e
@ -37,7 +37,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"rule.description":{"value":".*AuthorizeSecurity.*"}}}"
|
"value": {"regexp":{"rule.description":".*AuthorizeSecurity.*"}}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
@ -77,7 +77,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"rule.description":{"value":".*RevokeSecurity.*"}}}"
|
"value": {"regexp":{"rule.description":".*RevokeSecurity.*"}}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
@ -117,7 +117,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"data.aws.eventName":{"value":".*Instances.*"}}}"
|
"value": {"regexp":{"data.aws.eventName":".*Instances.*"}}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
@ -157,7 +157,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"rule.description":{"value":".*Login?Success.*"}}}"
|
"value": {"regexp":{"rule.description":".*Login?Success.*"}}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
@ -211,7 +211,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"rule.description":{"value":".*Security.*"}}}"
|
"value": {"regexp":{"rule.description":".*Security.*"}}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
@ -251,7 +251,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"rule.description":{"value":".*Login?Success.*"}}}"
|
"value": {"regexp":{"rule.description":".*Login?Success.*"}}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
|
@ -245,7 +245,7 @@ export default [
|
|||||||
"_id": "Wazuh-App-Overview-FIM-Root-user-file-changes",
|
"_id": "Wazuh-App-Overview-FIM-Root-user-file-changes",
|
||||||
"_source": {
|
"_source": {
|
||||||
"title": "Root user file changes",
|
"title": "Root user file changes",
|
||||||
"visState": "{\"title\":\"Root user file changes\",\"type\":\"pie\",\"params\":{\"isDonut\":false,\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"type\":\"pie\",\"legendPosition\":\"right\",\"labels\":{\"show\":false,\"values\":true,\"last_level\":true,\"truncate\":100}},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"syscheck.path\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}]}",
|
"visState": "{\"title\":\"Root user file changes\",\"type\":\"pie\",\"params\":{\"isDonut\":false,\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"type\":\"pie\",\"legendPosition\":\"right\",\"labels\":{\"show\":false,\"values\":true,\"last_level\":true,\"truncate\":100}},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"syscheck.path\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}]}",
|
||||||
"uiStateJSON": "{}",
|
"uiStateJSON": "{}",
|
||||||
"description": "",
|
"description": "",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
@ -287,7 +287,7 @@ export default [
|
|||||||
{
|
{
|
||||||
"query": {
|
"query": {
|
||||||
"regexp": {
|
"regexp": {
|
||||||
"syscheck.perm_after": "[0-7]{5}([2367]).*"
|
"syscheck.perm_after": "[0-7]{5}([2367])"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"meta": {
|
"meta": {
|
||||||
@ -297,7 +297,7 @@ export default [
|
|||||||
"alias": null,
|
"alias": null,
|
||||||
"type": "custom",
|
"type": "custom",
|
||||||
"key": "query",
|
"key": "query",
|
||||||
"value": "{"regexp":{"syscheck.perm_after":"[0-7]{5}([2367]).*"}}"
|
"value": {"regexp":{"syscheck.perm_after": "[0-7]{5}([2367])" }}
|
||||||
},
|
},
|
||||||
"$state": {
|
"$state": {
|
||||||
"store": "appState"
|
"store": "appState"
|
||||||
|
Loading…
Reference in New Issue
Block a user