added Malcolm
This commit is contained in:
		| @@ -0,0 +1,491 @@ | ||||
| { | ||||
|   "version": "7.10.0", | ||||
|   "objects": [ | ||||
|     { | ||||
|       "id": "36ed695f-edcc-47c1-b0ec-50d20c93ce0f", | ||||
|       "type": "dashboard", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM2OCwxXQ==", | ||||
|       "attributes": { | ||||
|         "title": "Intel", | ||||
|         "hits": 0, | ||||
|         "description": "", | ||||
|         "panelsJSON": "[{\"gridData\":{\"w\":8,\"h\":48,\"x\":0,\"y\":0,\"i\":\"2\"},\"panelIndex\":\"2\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_0\",\"embeddableConfig\":{}},{\"embeddableConfig\":{},\"gridData\":{\"w\":32,\"h\":8,\"x\":16,\"y\":0,\"i\":\"3\"},\"panelIndex\":\"3\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_1\"},{\"gridData\":{\"w\":20,\"h\":16,\"x\":8,\"y\":8,\"i\":\"5\"},\"panelIndex\":\"5\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_2\",\"embeddableConfig\":{}},{\"embeddableConfig\":{},\"gridData\":{\"w\":20,\"h\":24,\"x\":28,\"y\":24,\"i\":\"6\"},\"panelIndex\":\"6\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_3\"},{\"embeddableConfig\":{},\"gridData\":{\"w\":16,\"h\":24,\"x\":0,\"y\":72,\"i\":\"7\"},\"panelIndex\":\"7\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_4\"},{\"embeddableConfig\":{},\"gridData\":{\"w\":16,\"h\":24,\"x\":16,\"y\":72,\"i\":\"8\"},\"panelIndex\":\"8\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_5\"},{\"embeddableConfig\":{},\"gridData\":{\"w\":20,\"h\":24,\"x\":8,\"y\":24,\"i\":\"11\"},\"panelIndex\":\"11\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_6\"},{\"embeddableConfig\":{},\"gridData\":{\"w\":28,\"h\":24,\"x\":20,\"y\":48,\"i\":\"12\"},\"panelIndex\":\"12\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_7\"},{\"embeddableConfig\":{},\"gridData\":{\"w\":20,\"h\":24,\"x\":0,\"y\":48,\"i\":\"13\"},\"panelIndex\":\"13\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_8\"},{\"gridData\":{\"w\":48,\"h\":24,\"x\":0,\"y\":96,\"i\":\"14\"},\"panelIndex\":\"14\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_9\",\"embeddableConfig\":{\"columns\":[\"srcIp\",\"dstIp\",\"dstPort\",\"zeek.uid\",\"zeek.fuid\",\"_id\"],\"sort\":[\"firstPacket\",\"desc\"]}},{\"embeddableConfig\":{},\"gridData\":{\"w\":16,\"h\":24,\"x\":32,\"y\":72,\"i\":\"15\"},\"panelIndex\":\"15\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_10\"},{\"gridData\":{\"w\":20,\"h\":16,\"x\":28,\"y\":8,\"i\":\"16\"},\"panelIndex\":\"16\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_11\",\"embeddableConfig\":{}},{\"embeddableConfig\":{},\"gridData\":{\"w\":8,\"h\":8,\"x\":8,\"y\":0,\"i\":\"17\"},\"panelIndex\":\"17\",\"version\":\"7.3.0\",\"panelRefName\":\"panel_12\"}]", | ||||
|         "optionsJSON": "{\"useMargins\":true}", | ||||
|         "version": 1, | ||||
|         "timeRestore": false, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[],\"highlightAll\":true,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}}}" | ||||
|         } | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "name": "panel_0", | ||||
|           "type": "visualization", | ||||
|           "id": "df9e399b-efa5-4e33-b0ac-a7668a8ac2b3" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_1", | ||||
|           "type": "visualization", | ||||
|           "id": "2721f49d-4e64-4145-9e81-85e856c20b37" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_2", | ||||
|           "type": "visualization", | ||||
|           "id": "ee52f4a1-4232-4c49-abee-accc05ea91aa" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_3", | ||||
|           "type": "visualization", | ||||
|           "id": "80cabf50-a849-4e24-a9c7-130cba1a8141" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_4", | ||||
|           "type": "visualization", | ||||
|           "id": "cd5ecdc5-e74d-469f-a772-f03562fa2e33" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_5", | ||||
|           "type": "visualization", | ||||
|           "id": "8296467e-ce1d-493c-a46c-948ec4fd7c83" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_6", | ||||
|           "type": "visualization", | ||||
|           "id": "a2d0a8bb-a6a2-4a1e-826c-0ce3ea8ff074" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_7", | ||||
|           "type": "visualization", | ||||
|           "id": "a27464ba-582d-405f-931d-003d8252ff4a" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_8", | ||||
|           "type": "visualization", | ||||
|           "id": "2d2f90e4-cac7-47c5-b63d-077b596ba45b" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_9", | ||||
|           "type": "search", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_10", | ||||
|           "type": "visualization", | ||||
|           "id": "d23ba78a-f080-4bc1-bdcf-114cb081773f" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_11", | ||||
|           "type": "visualization", | ||||
|           "id": "fa56cc7f-fb00-47fb-becb-1b1fdfea908e" | ||||
|         }, | ||||
|         { | ||||
|           "name": "panel_12", | ||||
|           "type": "visualization", | ||||
|           "id": "AWDG-Qf8xQT5EBNmq4G5" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "dashboard": "7.9.3" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "df9e399b-efa5-4e33-b0ac-a7668a8ac2b3", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:25:09.616Z", | ||||
|       "version": "Wzg3MiwxXQ==", | ||||
|       "attributes": { | ||||
|         "title": "Zeek Logs", | ||||
|         "visState": "{\"title\":\"Zeek Logs\",\"type\":\"markdown\",\"params\":{\"markdown\":\"### General\\n[Overview](/kibana/app/dashboards#/view/0ad3d7c2-3441-485e-9dfe-dbb22e84e576)  \\n[Security Overview](/kibana/app/dashboards#/view/95479950-41f2-11ea-88fa-7151df485405)  \\n[ICS/IoT Security Overview](/kibana/app/dashboards#/view/4a4bde20-4760-11ea-949c-bbb5a9feecbf)  \\n[Connections](/kibana/app/dashboards#/view/abdd7550-2c7c-40dc-947e-f6d186a158c4)  \\n[Actions and Results](/kibana/app/dashboards#/view/a33e0a50-afcd-11ea-993f-b7d8522a8bed)  \\n[Files](/kibana/app/dashboards#/view/9ee51f94-3316-4fc5-bd89-93a52af69714)  \\n[Executables](/kibana/app/dashboards#/view/0a490422-0ce9-44bf-9a2d-19329ddde8c3)  \\n[Software](/kibana/app/dashboards#/view/87d990cc-9e0b-41e5-b8fe-b10ae1da0c85)  \\n[Notices](/kibana/app/dashboards#/view/f1f09567-fc7f-450b-a341-19d2f2bb468b)  \\n[Weird](/kibana/app/dashboards#/view/1fff49f6-0199-4a0f-820b-721aff9ff1f1)  \\n[Signatures](/kibana/app/dashboards#/view/665d1610-523d-11e9-a30e-e3576242f3ed)  \\n[Intel Feeds](/kibana/app/dashboards#/view/36ed695f-edcc-47c1-b0ec-50d20c93ce0f)  \\n[↪ Arkime](/sessions)  \\n\\n### Common Protocols\\n[DCE/RPC](/kibana/app/dashboards#/view/432af556-c5c0-4cc3-8166-b274b4e3a406)   ●   [DHCP](/kibana/app/dashboards#/view/2d98bb8e-214c-4374-837b-20e1bcd63a5e)   ●   [DNS](/kibana/app/dashboards#/view/2cf94cd0-ecab-40a5-95a7-8419f3a39cd9)   ●   [FTP](/kibana/app/dashboards#/view/078b9aa5-9bd4-4f02-ae5e-cf80fa6f887b) / [TFTP](/kibana/app/dashboards#/view/bf5efbb0-60f1-11eb-9d60-dbf0411cfc48)   ●   [HTTP](/kibana/app/dashboards#/view/37041ee1-79c0-4684-a436-3173b0e89876)   ●   [IRC](/kibana/app/dashboards#/view/76f2f912-80da-44cd-ab66-6a73c8344cc3)   ●   [Kerberos](/kibana/app/dashboards#/view/82da3101-2a9c-4ae2-bb61-d447a3fbe673)   ●   [LDAP](/kibana/app/dashboards#/view/05e3e000-f118-11e9-acda-83a8e29e1a24)   ●   [MySQL](/kibana/app/dashboards#/view/50ced171-1b10-4c3f-8b67-2db9635661a6)   ●   [NTLM](/kibana/app/dashboards#/view/543118a9-02d7-43fe-b669-b8652177fc37)   ●   [NTP](/kibana/app/dashboards#/view/af5df620-eeb6-11e9-bdef-65a192b7f586)   ●   [QUIC](/kibana/app/dashboards#/view/11ddd980-e388-11e9-b568-cf17de8e860c)   ●   [RADIUS](/kibana/app/dashboards#/view/ae79b7d1-4281-4095-b2f6-fa7eafda9970)   ●   [RDP](/kibana/app/dashboards#/view/7f41913f-cba8-43f5-82a8-241b7ead03e0)   ●   [RFB](/kibana/app/dashboards#/view/f77bf097-18a8-465c-b634-eb2acc7a4f26)   ●   [SIP](/kibana/app/dashboards#/view/0b2354ae-0fe9-4fd9-b156-1c3870e5c7aa)   ●   [SMB](/kibana/app/dashboards#/view/42e831b9-41a9-4f35-8b7d-e1566d368773)   ●   [SMTP](/kibana/app/dashboards#/view/bb827f8e-639e-468c-93c8-9f5bc132eb8f)   ●   [SNMP](/kibana/app/dashboards#/view/4e5f106e-c60a-4226-8f64-d534abb912ab)   ●   [SSH](/kibana/app/dashboards#/view/caef3ade-d289-4d05-a511-149f3e97f238)   ●   [SSL](/kibana/app/dashboards#/view/7f77b58a-df3e-4cc2-b782-fd7f8bad8ffb) / [X.509 Certificates](/kibana/app/dashboards#/view/024062a6-48d6-498f-a91a-3bf2da3a3cd3)   ●   [Syslog](/kibana/app/dashboards#/view/92985909-dc29-4533-9e80-d3182a0ecf1d)   ●   [TDS](/kibana/app/dashboards#/view/bed185a0-ef82-11e9-b38a-2db3ee640e88) / [TDS RPC](/kibana/app/dashboards#/view/32587740-ef88-11e9-b38a-2db3ee640e88) / [TDS SQL](/kibana/app/dashboards#/view/fa141950-ef89-11e9-b38a-2db3ee640e88)   ●   [Telnet / rlogin / rsh](/kibana/app/dashboards#/view/c2549e10-7f2e-11ea-9f8a-1fe1327e2cd2)   ●   [Tunnels](/kibana/app/dashboards#/view/11be6381-beef-40a7-bdce-88c5398392fc)\\n\\n### ICS/IoT Protocols\\n[BACnet](/kibana/app/dashboards#/view/2bec1490-eb94-11e9-a384-0fcf32210194)   ●   [BSAP](/kibana/app/dashboards#/view/ca5799a0-56b5-11eb-b749-576de068f8ad)   ●   [DNP3](/kibana/app/dashboards#/view/870a5862-6c26-4a08-99fd-0c06cda85ba3)   ●   [EtherCAT](/kibana/app/dashboards#/view/4a073440-b286-11eb-a4d4-09fa12a6ebd4)   ●   [EtherNet/IP](/kibana/app/dashboards#/view/29a1b290-eb98-11e9-a384-0fcf32210194)   ●   [Modbus](/kibana/app/dashboards#/view/152f29dc-51a2-4f53-93e9-6e92765567b8)   ●   [MQTT](/kibana/app/dashboards#/view/87a32f90-ef58-11e9-974e-9d600036d105)   ●   [PROFINET](/kibana/app/dashboards#/view/a7514350-eba6-11e9-a384-0fcf32210194)   ●   [S7comm](/kibana/app/dashboards#/view/e76d05c0-eb9f-11e9-a384-0fcf32210194)   ●   [Best Guess](/kibana/app/dashboards#/view/12e3a130-d83b-11eb-a0b0-f328ce09b0b7)\",\"type\":\"markdown\",\"fontSize\":10,\"openLinksInNewTab\":false},\"aggs\":[]}", | ||||
|         "uiStateJSON": "{}", | ||||
|         "description": "", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"query\":{\"query\":{\"query_string\":{\"query\":\"*\"}},\"language\":\"lucene\"},\"filter\":[]}" | ||||
|         } | ||||
|       }, | ||||
|       "references": [], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "2721f49d-4e64-4145-9e81-85e856c20b37", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3MCwxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Log Count Over Time\",\"type\":\"line\",\"params\":{\"grid\":{\"categoryLines\":false,\"style\":{\"color\":\"#eee\"}},\"categoryAxes\":[{\"id\":\"CategoryAxis-1\",\"type\":\"category\",\"position\":\"bottom\",\"show\":true,\"style\":{},\"scale\":{\"type\":\"linear\"},\"labels\":{\"show\":true,\"truncate\":100},\"title\":{\"text\":\"firstPacket per 12 hours\"}}],\"valueAxes\":[{\"id\":\"ValueAxis-1\",\"name\":\"LeftAxis-1\",\"type\":\"value\",\"position\":\"left\",\"show\":true,\"style\":{},\"scale\":{\"type\":\"linear\",\"mode\":\"normal\"},\"labels\":{\"show\":true,\"rotate\":0,\"filter\":false,\"truncate\":100},\"title\":{\"text\":\"Count\"}}],\"seriesParams\":[{\"show\":true,\"mode\":\"normal\",\"type\":\"line\",\"drawLinesBetweenPoints\":true,\"showCircles\":true,\"interpolate\":\"linear\",\"lineWidth\":2,\"data\":{\"id\":\"1\",\"label\":\"Count\"},\"valueAxis\":\"ValueAxis-1\"}],\"addTooltip\":true,\"addLegend\":true,\"legendPosition\":\"right\",\"showCircles\":true,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":true,\"radiusRatio\":9,\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"firstPacket\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Log Count Over Time", | ||||
|         "uiStateJSON": "{}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "ee52f4a1-4232-4c49-abee-accc05ea91aa", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3MSwxXQ==", | ||||
|       "attributes": { | ||||
|         "title": "Intel - Seen", | ||||
|         "visState": "{\"title\":\"Intel - Seen\",\"type\":\"pie\",\"params\":{\"addTooltip\":true,\"addLegend\":true,\"legendPosition\":\"right\",\"isDonut\":true,\"type\":\"pie\",\"labels\":{\"show\":false,\"values\":true,\"last_level\":true,\"truncate\":100}},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"zeek_intel.seen_where\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":20,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Seen (Where)\"}}]}", | ||||
|         "uiStateJSON": "{\"vis\":{\"legendOpen\":true}}", | ||||
|         "description": "", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[],\"query\":{\"query\":\"\",\"language\":\"lucene\"}}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "80cabf50-a849-4e24-a9c7-130cba1a8141", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3MiwxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Source\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"zeek_intel.sources\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":20,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Source\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Source", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "cd5ecdc5-e74d-469f-a772-f03562fa2e33", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3MywxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Source IP Address\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"srcIp\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"IP Address\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Source IP Address", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "8296467e-ce1d-493c-a46c-948ec4fd7c83", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3NCwxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Destination IP Address\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"dstIp\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":20,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"IP Address\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Destination IP Address", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "a2d0a8bb-a6a2-4a1e-826c-0ce3ea8ff074", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3NSwxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Indicator\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"zeek_intel.indicator\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":20,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Indicator\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Indicator", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "a27464ba-582d-405f-931d-003d8252ff4a", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3NiwxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - MIME Type\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"zeek_intel.file_mime_type\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"MIME Type\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - MIME Type", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "2d2f90e4-cac7-47c5-b63d-077b596ba45b", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3NywxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Matched\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"zeek_intel.matched\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Type Matched\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Matched", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798", | ||||
|       "type": "search", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3OCwxXQ==", | ||||
|       "attributes": { | ||||
|         "sort": [ | ||||
|           [ | ||||
|             "firstPacket", | ||||
|             "desc" | ||||
|           ] | ||||
|         ], | ||||
|         "hits": 0, | ||||
|         "description": "", | ||||
|         "title": "Intel - Logs", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"highlightAll\":true,\"version\":true,\"filter\":[],\"query\":{\"query_string\":{\"query\":\"zeek.logType:intel\",\"analyze_wildcard\":true}},\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}" | ||||
|         }, | ||||
|         "columns": [ | ||||
|           "srcIp", | ||||
|           "dstIp", | ||||
|           "dstPort", | ||||
|           "zeek.uid", | ||||
|           "zeek.fuid", | ||||
|           "_id" | ||||
|         ] | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "name": "kibanaSavedObjectMeta.searchSourceJSON.index", | ||||
|           "type": "index-pattern", | ||||
|           "id": "sessions2-*" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "search": "7.9.3" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "d23ba78a-f080-4bc1-bdcf-114cb081773f", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM3OSwxXQ==", | ||||
|       "attributes": { | ||||
|         "visState": "{\"title\":\"Intel - Destination Port\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"dstPort\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Port\"}}],\"listeners\":{}}", | ||||
|         "description": "", | ||||
|         "title": "Intel - Destination Port", | ||||
|         "uiStateJSON": "{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "fa56cc7f-fb00-47fb-becb-1b1fdfea908e", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM4MCwxXQ==", | ||||
|       "attributes": { | ||||
|         "title": "Intel - Indicator Type", | ||||
|         "visState": "{\"title\":\"Intel - Indicator Type\",\"type\":\"histogram\",\"params\":{\"grid\":{\"categoryLines\":false,\"style\":{\"color\":\"#eee\"}},\"categoryAxes\":[{\"id\":\"CategoryAxis-1\",\"type\":\"category\",\"position\":\"bottom\",\"show\":true,\"style\":{},\"scale\":{\"type\":\"linear\"},\"labels\":{\"show\":true,\"truncate\":100,\"rotate\":0},\"title\":{\"text\":\"Indicator Type\"}}],\"valueAxes\":[{\"id\":\"ValueAxis-1\",\"name\":\"LeftAxis-1\",\"type\":\"value\",\"position\":\"left\",\"show\":true,\"style\":{},\"scale\":{\"type\":\"linear\",\"mode\":\"normal\"},\"labels\":{\"show\":true,\"rotate\":0,\"filter\":false,\"truncate\":100},\"title\":{\"text\":\"Count\"}}],\"seriesParams\":[{\"show\":\"true\",\"type\":\"histogram\",\"mode\":\"stacked\",\"data\":{\"label\":\"Count\",\"id\":\"1\"},\"valueAxis\":\"ValueAxis-1\",\"drawLinesBetweenPoints\":true,\"showCircles\":true}],\"addTooltip\":true,\"addLegend\":true,\"legendPosition\":\"right\",\"times\":[],\"addTimeMarker\":false,\"type\":\"histogram\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"zeek_intel.indicator_type\",\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Indicator Type\"}}]}", | ||||
|         "uiStateJSON": "{\"vis\":{\"legendOpen\":false}}", | ||||
|         "description": "", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[],\"query\":{\"query\":\"\",\"language\":\"lucene\"}}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     }, | ||||
|     { | ||||
|       "id": "AWDG-Qf8xQT5EBNmq4G5", | ||||
|       "type": "visualization", | ||||
|       "namespaces": [ | ||||
|         "default" | ||||
|       ], | ||||
|       "updated_at": "2021-02-10T21:24:23.239Z", | ||||
|       "version": "WzM4MSwxXQ==", | ||||
|       "attributes": { | ||||
|         "title": "Intel - Log Count", | ||||
|         "visState": "{\"title\":\"Intel - Log Count\",\"type\":\"metric\",\"params\":{\"addTooltip\":true,\"addLegend\":false,\"type\":\"gauge\",\"gauge\":{\"verticalSplit\":false,\"autoExtend\":false,\"percentageMode\":false,\"gaugeType\":\"Metric\",\"gaugeStyle\":\"Full\",\"backStyle\":\"Full\",\"orientation\":\"vertical\",\"colorSchema\":\"Green to Red\",\"gaugeColorMode\":\"None\",\"useRange\":false,\"colorsRange\":[{\"from\":0,\"to\":100}],\"invertColors\":false,\"labels\":{\"show\":false,\"color\":\"black\"},\"scale\":{\"show\":false,\"labels\":false,\"color\":\"#333\",\"width\":2},\"type\":\"simple\",\"style\":{\"fontSize\":\"30\",\"bgColor\":false,\"labelColor\":false,\"subText\":\"\",\"bgFill\":\"#FB9E00\"}}},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}", | ||||
|         "uiStateJSON": "{\"vis\":{\"defaultColors\":{\"0 - 100\":\"rgb(0,104,55)\"}}}", | ||||
|         "description": "", | ||||
|         "version": 1, | ||||
|         "kibanaSavedObjectMeta": { | ||||
|           "searchSourceJSON": "{\"filter\":[]}" | ||||
|         }, | ||||
|         "savedSearchRefName": "search_0" | ||||
|       }, | ||||
|       "references": [ | ||||
|         { | ||||
|           "type": "search", | ||||
|           "name": "search_0", | ||||
|           "id": "5154d8e9-c83e-4d42-bde3-33ad0c7d1798" | ||||
|         } | ||||
|       ], | ||||
|       "migrationVersion": { | ||||
|         "visualization": "7.10.0" | ||||
|       } | ||||
|     } | ||||
|   ] | ||||
| } | ||||
		Reference in New Issue
	
	Block a user