Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
812 changes: 399 additions & 413 deletions dashboards/Data Explorer/AWS VPC Flow.json

Large diffs are not rendered by default.

506 changes: 126 additions & 380 deletions dashboards/Data Explorer/Connections.json

Large diffs are not rendered by default.

199 changes: 135 additions & 64 deletions dashboards/Data Explorer/DNS.json

Large diffs are not rendered by default.

288 changes: 201 additions & 87 deletions dashboards/Data Explorer/Files.json

Large diffs are not rendered by default.

338 changes: 150 additions & 188 deletions dashboards/Data Explorer/HTTP.json

Large diffs are not rendered by default.

66 changes: 28 additions & 38 deletions dashboards/Data Explorer/SSL.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"dashboards": [
{
"dashboard": {
"name": "1610311b-37d2-458f-98d5-b45b9b3d4e45",
"name": "09b2b3c4-0ace-449f-92a8-5a348c312715",
"displayName": "Corelight → Data Explorer → SSL",
"definition": {
"filters": [
Expand All @@ -20,9 +20,9 @@
],
"displayName": "Global Time Filter",
"chartIds": [
"ca8da243-8a64-47c8-b281-45a7cfbf36ba",
"10edc301-015c-4107-a798-5724ab26224b",
"af4da1d3-eb70-4858-8841-5d5885bc0599"
"34e47bbe-f925-4f1f-84f8-9b4f0f274201",
"29788b50-d3e8-461d-9467-abb11caa4e6e",
"4230f1bf-cc19-4484-880c-a2c48bb4dff6"
],
"isStandardTimeRangeFilter": true,
"isStandardTimeRangeFilterEnabled": true
Expand All @@ -41,15 +41,15 @@
],
"displayName": "Corelight Sensor",
"chartIds": [
"10edc301-015c-4107-a798-5724ab26224b",
"ca8da243-8a64-47c8-b281-45a7cfbf36ba",
"af4da1d3-eb70-4858-8841-5d5885bc0599"
"29788b50-d3e8-461d-9467-abb11caa4e6e",
"34e47bbe-f925-4f1f-84f8-9b4f0f274201",
"4230f1bf-cc19-4484-880c-a2c48bb4dff6"
]
}
],
"charts": [
{
"dashboardChart": "10edc301-015c-4107-a798-5724ab26224b",
"dashboardChart": "29788b50-d3e8-461d-9467-abb11caa4e6e",
"chartLayout": {
"startX": 0,
"spanX": 96,
Expand All @@ -62,7 +62,7 @@
]
},
{
"dashboardChart": "ca8da243-8a64-47c8-b281-45a7cfbf36ba",
"dashboardChart": "34e47bbe-f925-4f1f-84f8-9b4f0f274201",
"chartLayout": {
"startX": 0,
"spanX": 48,
Expand All @@ -75,7 +75,7 @@
]
},
{
"dashboardChart": "af4da1d3-eb70-4858-8841-5d5885bc0599",
"dashboardChart": "4230f1bf-cc19-4484-880c-a2c48bb4dff6",
"chartLayout": {
"startX": 48,
"spanX": 48,
Expand All @@ -90,15 +90,15 @@
]
},
"type": "CUSTOM",
"etag": "6f3ee367cfc9080206cb173f9ee55765d03796d9b30aa746a8f0637dd7471057",
"etag": "706030355e52f52a67a9d6f78f3471ac7ed7cd4fb6129d315301c07978c88c0b",
"access": "DASHBOARD_PRIVATE"
},
"dashboardCharts": [
{
"name": "10edc301-015c-4107-a798-5724ab26224b",
"name": "29788b50-d3e8-461d-9467-abb11caa4e6e",
"displayName": "Top Ciphers",
"chartDatasource": {
"dashboardQuery": "87f0902c-d06d-4d8d-8aa4-466e883486e7",
"dashboardQuery": "0a2026e9-0f41-41ee-bc14-202da7c9e9fb",
"dataSources": [
"UDM"
]
Expand Down Expand Up @@ -137,13 +137,13 @@
"groupingType": "Off"
},
"tileType": "TILE_TYPE_VISUALIZATION",
"etag": "6f03304bc2f879762eefb9d7f36e7cc30596c35cc1ea8f423843534966959207"
"etag": "f815fc71500c9d7e6fba8d8e5616b2c56c59a1b96b1690989a7edd2a7acb252d"
},
{
"name": "ca8da243-8a64-47c8-b281-45a7cfbf36ba",
"name": "34e47bbe-f925-4f1f-84f8-9b4f0f274201",
"displayName": "Top Certificate Subjects",
"chartDatasource": {
"dashboardQuery": "45760ea9-ea20-4b10-a6e0-42d58eb845d3",
"dashboardQuery": "e341cfa8-2908-4757-975f-ae59c2e55739",
"dataSources": [
"UDM"
]
Expand Down Expand Up @@ -177,7 +177,7 @@
"groupingType": "Off"
},
"tileType": "TILE_TYPE_VISUALIZATION",
"etag": "de4a39461b5fe26fce18b60b038ab0f1cc1daacf7a4ecbb36fdee0af6a8d972a",
"etag": "73e28d1a5bdb3191288ada95b96ebd0f05c856ce58e83ada69be889d962e2bb7",
"drillDownConfig": {
"leftDrillDowns": [
{
Expand All @@ -191,10 +191,10 @@
}
},
{
"name": "af4da1d3-eb70-4858-8841-5d5885bc0599",
"name": "4230f1bf-cc19-4484-880c-a2c48bb4dff6",
"displayName": "Top Local Responders - Validation Status",
"chartDatasource": {
"dashboardQuery": "9bfc0d96-1d37-4f26-b0e2-9d2ccd1a7183",
"dashboardQuery": "cc6a3ab6-cfd4-4a5d-b5d1-f715c4ef91dc",
"dataSources": [
"UDM"
]
Expand Down Expand Up @@ -228,53 +228,43 @@
"groupingType": "Off"
},
"tileType": "TILE_TYPE_VISUALIZATION",
"etag": "03b7b8fdcd3e54ed0a5f15337034275058fa0ec0ec19a9298d02be4b4af95787",
"drillDownConfig": {
"leftDrillDowns": [
{
"id": "validation_status",
"displayName": "Run Search on Validation Status",
"defaultSettings": {
"enabled": true
}
}
]
}
"etag": "cdc00ee9c241f7c3f647bb4e835470190ca884b17017fa6a4d1c4e251fdc6dfc",
"drillDownConfig": {}
}
],
"dashboardQueries": [
{
"name": "9bfc0d96-1d37-4f26-b0e2-9d2ccd1a7183",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type=\"ssl\"\r\n$validation_status=security_result.description\r\n$validation_status!=\"\"\r\n$local_orig=if(principal.ip in cidr %internal_cidr_list, \"true\", \"false\")\r\n$local_resp=if(target.ip in cidr %internal_cidr_list, \"true\", \"false\") \r\n($local_orig=\"true\" AND $local_resp=\"true\") OR ($local_orig=\"false\" AND $local_resp=\"true\")\r\nmatch:\r\n $validation_status\r\noutcome:\r\n $count=count_distinct(metadata.id)\r\norder:\r\n $count desc \r\nlimit:\r\n 10\r\n",
"name": "cc6a3ab6-cfd4-4a5d-b5d1-f715c4ef91dc",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type=\"ssl\"\r\n$validation_status=security_result.description\r\n$validation_status!=\"\"\r\n((principal.ip in cidr %internal_cidr_list) AND (target.ip in cidr %internal_cidr_list)) OR (not(principal.ip in cidr %internal_cidr_list) AND (target.ip in cidr %internal_cidr_list))\r\nmatch:\r\n $validation_status\r\noutcome:\r\n $count=count_distinct(metadata.id)\r\norder:\r\n $count desc \r\nlimit:\r\n 10",
"input": {
"relativeTime": {
"timeUnit": "DAY",
"startTimeVal": "1"
}
},
"etag": "2794e30c732e5abef1835d6a6da85aeaf9f7a39edbbfd13d22ab4e6ac9de9d1b"
"etag": "35117e58b59078f2506ebe2f5b9262dacddbbdd86b2688e01c9ba5466984aa73"
},
{
"name": "87f0902c-d06d-4d8d-8aa4-466e883486e7",
"name": "0a2026e9-0f41-41ee-bc14-202da7c9e9fb",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type=\"ssl\"\r\n$cipher=network.tls.cipher\r\n$cipher!=\"\"\r\nmatch:\r\n $cipher\r\noutcome:\r\n $count=count_distinct(metadata.id)\r\norder:\r\n $count desc \r\nlimit:\r\n 10\r\n",
"input": {
"relativeTime": {
"timeUnit": "DAY",
"startTimeVal": "1"
}
},
"etag": "e12f5534e07a14a47e663f1b12ecc94c33da306b9e5f39c0d769c94a48753a6d"
"etag": "f060c45ea99b65456b389288494c81d8381d3617978421a4187466e42033590e"
},
{
"name": "45760ea9-ea20-4b10-a6e0-42d58eb845d3",
"name": "e341cfa8-2908-4757-975f-ae59c2e55739",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type=\"ssl\"\r\n$server_name=network.tls.client.server_name\r\n$server_name!=\"\"\r\nmatch:\r\n $server_name\r\noutcome:\r\n $count=count_distinct(metadata.id)\r\norder:\r\n $count desc \r\nlimit:\r\n 10\r\n",
"input": {
"relativeTime": {
"timeUnit": "DAY",
"startTimeVal": "1"
}
},
"etag": "740c03b0242f08b27dfa95e264996aed6f7ed2c5d2410cd49ed2c4a950e0c783"
"etag": "086b64bec914f909e4ecb1469e72a14c39c0394d452936c6b452048e9efe80a8"
}
]
}
Expand Down
54 changes: 27 additions & 27 deletions dashboards/Data Explorer/x509.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"dashboards": [
{
"dashboard": {
"name": "ffa1fb58-6762-492a-9b67-4d9361ac76b7",
"name": "e0e00777-708c-4f28-b91c-354cb36d7801",
"displayName": "Corelight → Data Explorer → x509",
"definition": {
"filters": [
Expand All @@ -20,9 +20,9 @@
],
"displayName": "Global Time Filter",
"chartIds": [
"c981a126-162f-415a-8f8b-efa7817aa591",
"799438d8-0cd7-4497-950d-c55ae1801f4e",
"04b95d7d-1f95-4f6d-b27a-b5377c342b75"
"3ed38560-aea7-4f9e-a57c-4ec003bb7870",
"c5eef646-dbff-4a69-8198-3862a7fe52a1",
"c314c523-c9b2-4313-9212-71f073a27d8c"
],
"isStandardTimeRangeFilter": true,
"isStandardTimeRangeFilterEnabled": true
Expand All @@ -41,15 +41,15 @@
],
"displayName": "Corelight Sensor",
"chartIds": [
"c981a126-162f-415a-8f8b-efa7817aa591",
"799438d8-0cd7-4497-950d-c55ae1801f4e",
"04b95d7d-1f95-4f6d-b27a-b5377c342b75"
"3ed38560-aea7-4f9e-a57c-4ec003bb7870",
"c5eef646-dbff-4a69-8198-3862a7fe52a1",
"c314c523-c9b2-4313-9212-71f073a27d8c"
]
}
],
"charts": [
{
"dashboardChart": "799438d8-0cd7-4497-950d-c55ae1801f4e",
"dashboardChart": "c5eef646-dbff-4a69-8198-3862a7fe52a1",
"chartLayout": {
"startX": 0,
"spanX": 48,
Expand All @@ -62,7 +62,7 @@
]
},
{
"dashboardChart": "04b95d7d-1f95-4f6d-b27a-b5377c342b75",
"dashboardChart": "c314c523-c9b2-4313-9212-71f073a27d8c",
"chartLayout": {
"startX": 48,
"spanX": 48,
Expand All @@ -75,7 +75,7 @@
]
},
{
"dashboardChart": "c981a126-162f-415a-8f8b-efa7817aa591",
"dashboardChart": "3ed38560-aea7-4f9e-a57c-4ec003bb7870",
"chartLayout": {
"startX": 0,
"spanX": 96,
Expand All @@ -90,15 +90,15 @@
]
},
"type": "CUSTOM",
"etag": "82af039dc116b41cd574a1f936c09460b45688a54dfc4f620c9857b4f65d932f",
"etag": "262ea13e13a8b2f39849f9e6ea72340161a974b24d888314a60ed48ce8f8bc86",
"access": "DASHBOARD_PRIVATE"
},
"dashboardCharts": [
{
"name": "04b95d7d-1f95-4f6d-b27a-b5377c342b75",
"name": "c314c523-c9b2-4313-9212-71f073a27d8c",
"displayName": "x509 Rare Subjects",
"chartDatasource": {
"dashboardQuery": "f1ff5ba1-24ac-4377-9f19-3c132e9baf31",
"dashboardQuery": "fa2df226-5427-4e43-9099-ec9f4a9fe3d2",
"dataSources": [
"UDM"
]
Expand Down Expand Up @@ -132,7 +132,7 @@
"groupingType": "Off"
},
"tileType": "TILE_TYPE_VISUALIZATION",
"etag": "e8952a56701ca683c694d52ed869b7972572c2f98f7328bc052ab7a0a501c999",
"etag": "1e3c0180156f01dd1498969683c174854e8fecd549e786609424a389a80f5dee",
"drillDownConfig": {
"leftDrillDowns": [
{
Expand All @@ -146,10 +146,10 @@
}
},
{
"name": "799438d8-0cd7-4497-950d-c55ae1801f4e",
"name": "c5eef646-dbff-4a69-8198-3862a7fe52a1",
"displayName": "x509 Top Subjects",
"chartDatasource": {
"dashboardQuery": "bf673c4a-5f77-46aa-b748-d2dc4d29688c",
"dashboardQuery": "baf43451-39e0-40ef-b1e7-ce7649144ae9",
"dataSources": [
"UDM"
]
Expand Down Expand Up @@ -183,7 +183,7 @@
"groupingType": "Off"
},
"tileType": "TILE_TYPE_VISUALIZATION",
"etag": "eec62d657f8f84df7963fd76a76416d246616e9c14f36d68bb20dd2113852ebf",
"etag": "ad338df1de0046f79ad294ca84ae2dbf089702a7abb2730727602c3e16da47ea",
"drillDownConfig": {
"leftDrillDowns": [
{
Expand All @@ -197,10 +197,10 @@
}
},
{
"name": "c981a126-162f-415a-8f8b-efa7817aa591",
"name": "3ed38560-aea7-4f9e-a57c-4ec003bb7870",
"displayName": "x509 Expired Certificates",
"chartDatasource": {
"dashboardQuery": "a9c4b939-05a3-4733-b6f7-1064ad966069",
"dashboardQuery": "7f0a7b48-1aeb-45bb-bc78-8743a95a578c",
"dataSources": [
"UDM"
]
Expand Down Expand Up @@ -234,43 +234,43 @@
"groupingType": "Off"
},
"tileType": "TILE_TYPE_VISUALIZATION",
"etag": "ec5013e2cca04d0e9da70a69cc4f387a9a9d414b1fbaab94d60287beecc88236",
"etag": "e79ae6d2c32e2977ef405dafbf44cf849992e9423a2d00aaca762c93ae453622",
"drillDownConfig": {}
}
],
"dashboardQueries": [
{
"name": "f1ff5ba1-24ac-4377-9f19-3c132e9baf31",
"name": "fa2df226-5427-4e43-9099-ec9f4a9fe3d2",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type=\"x509\"\r\n$ssl_subject=about.domain.last_https_certificate.subject.common_name\r\n$ssl_subject!=\"\"\r\nmatch:\r\n $ssl_subject\r\noutcome:\r\n $count=count_distinct(metadata.id)\r\norder:\r\n $count asc \r\nlimit:\r\n 10",
"input": {
"relativeTime": {
"timeUnit": "DAY",
"startTimeVal": "1"
}
},
"etag": "db916f92dab0e0ba7b7adcaacde9aa749b17bfa9b6bba0ad7a6df776693ed167"
"etag": "9430ed6fa539ae4be029af8b2442b933037f30412907536c5dc0f621fa022148"
},
{
"name": "bf673c4a-5f77-46aa-b748-d2dc4d29688c",
"name": "baf43451-39e0-40ef-b1e7-ce7649144ae9",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type=\"x509\"\r\n$ssl_subject=about.domain.last_https_certificate.subject.common_name\r\n$ssl_subject!=\"\"\r\nmatch:\r\n $ssl_subject\r\noutcome:\r\n $count=count_distinct(metadata.id)\r\norder:\r\n $count desc \r\nlimit:\r\n 10",
"input": {
"relativeTime": {
"timeUnit": "DAY",
"startTimeVal": "1"
}
},
"etag": "db167422d9aa45138ce80fc69aa3e61af72b9305d4a31ca3c8da0311e2a6ecfc"
"etag": "4e415bd2c6e696a5ca58d63c534947e81528b89ae0023c31b67048a01ae2b8f0"
},
{
"name": "a9c4b939-05a3-4733-b6f7-1064ad966069",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type = \"x509\" \r\n$certificate_expired = if(timestamp.current_seconds() > network.tls.server.certificate.not_after.seconds, \"Expired\", \"Not Expired\")\r\n$certificate_expired=\"Expired\"\r\n$not_after=timestamp.get_timestamp(network.tls.server.certificate.not_after.seconds)\r\nmatch:\r\n $not_after, about.domain.last_https_certificate.subject.common_name",
"name": "7f0a7b48-1aeb-45bb-bc78-8743a95a578c",
"query": "metadata.vendor_name=\"Corelight\"\r\nmetadata.product_event_type = \"x509\"\r\ntimestamp.current_seconds() > network.tls.server.certificate.not_after.seconds\r\n$not_after=timestamp.get_timestamp(network.tls.server.certificate.not_after.seconds)\r\nmatch:\r\n $not_after, about.domain.last_https_certificate.subject.common_name",
"input": {
"relativeTime": {
"timeUnit": "DAY",
"startTimeVal": "1"
}
},
"etag": "24e701b555182eabcd92aa0a694dac9361d0253b92af9257a9b7f1c7fe29e77c"
"etag": "da4ac55506ab43137b32913d4bb594ee8b0bad259978f26ee5e7474a5b1b8bf3"
}
]
}
Expand Down
Loading