Skip to content

Commit

Permalink
tmp
Browse files Browse the repository at this point in the history
  • Loading branch information
kvch committed Aug 4, 2021
1 parent fc404c0 commit 2d44a6c
Show file tree
Hide file tree
Showing 200 changed files with 1,955 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
{"attributes":{"columns":["agent.name","process.args","auditd.summary.actor.primary","auditd.summary.actor.secondary","process.executable"],"description":"","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[{\"$state\":{\"store\":\"appState\"},\"meta\":{\"alias\":null,\"disabled\":false,\"key\":\"event.module\",\"negate\":false,\"params\":{\"query\":\"auditd\",\"type\":\"phrase\"},\"type\":\"phrase\",\"value\":\"auditd\",\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index\"},\"query\":{\"match\":{\"event.module\":{\"query\":\"auditd\",\"type\":\"phrase\"}}}},{\"$state\":{\"store\":\"appState\"},\"meta\":{\"alias\":null,\"disabled\":false,\"key\":\"event.action\",\"negate\":false,\"params\":{\"query\":\"executed\",\"type\":\"phrase\"},\"type\":\"phrase\",\"value\":\"executed\",\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.filter[1].meta.index\"},\"query\":{\"match\":{\"event.action\":{\"query\":\"executed\",\"type\":\"phrase\"}}}}],\"highlightAll\":true,\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"version\":true,\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"sort":[["@timestamp","desc"]],"title":"Process Executions [Auditbeat Auditd] ECS","version":1},"coreMigrationVersion":"8.0.0","id":"d382f5b0-c1c6-11e7-8995-936807a28b16-ecs","migrationVersion":{"search":"7.9.3"},"references":[{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"},{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index","type":"index-pattern"},{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.filter[1].meta.index","type":"index-pattern"}],"type":"search","updated_at":"2021-08-04T16:35:57.797Z","version":"WzQ5NjksMV0="}
{"attributes":{"description":"Command executions","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"language\":\"kuery\",\"query\":\"\"}}"},"savedSearchRefName":"search_0","title":"Error Codes [Auditbeat Auditd] ECS","uiStateJSON":"{}","version":1,"visState":"{\"aggs\":[{\"enabled\":true,\"id\":\"1\",\"params\":{},\"schema\":\"metric\",\"type\":\"count\"},{\"enabled\":true,\"id\":\"2\",\"params\":{\"exclude\":\"0\",\"field\":\"auditd.data.exit\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":10},\"schema\":\"segment\",\"type\":\"terms\"}],\"params\":{\"addLegend\":true,\"addTooltip\":true,\"isDonut\":true,\"legendPosition\":\"right\",\"type\":\"pie\",\"palette\":{\"type\":\"palette\",\"name\":\"kibana_palette\"},\"distinctColors\":true},\"title\":\"Error Codes [Auditbeat Auditd] ECS\",\"type\":\"pie\"}"},"coreMigrationVersion":"8.0.0","id":"20a8e8d0-c1c8-11e7-8995-936807a28b16-ecs","migrationVersion":{"visualization":"7.14.0"},"references":[{"id":"d382f5b0-c1c6-11e7-8995-936807a28b16-ecs","name":"search_0","type":"search"}],"type":"visualization","updated_at":"2021-08-04T16:35:57.797Z","version":"WzQ5NjYsMV0="}
{"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"title":"Primary Username Tag Cloud [Auditbeat Auditd] ECS","uiStateJSON":"{}","version":1,"visState":"{\"aggs\":[{\"enabled\":true,\"id\":\"1\",\"params\":{},\"schema\":\"metric\",\"type\":\"count\"},{\"enabled\":true,\"id\":\"2\",\"params\":{\"field\":\"auditd.summary.actor.primary\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":10},\"schema\":\"segment\",\"type\":\"terms\"}],\"params\":{\"maxFontSize\":45,\"minFontSize\":18,\"orientation\":\"single\",\"scale\":\"linear\",\"palette\":{\"type\":\"palette\",\"name\":\"kibana_palette\"}},\"title\":\"Primary Username Tag Cloud [Auditbeat Auditd] ECS\",\"type\":\"tagcloud\"}"},"coreMigrationVersion":"8.0.0","id":"f81a6de0-c1c1-11e7-8995-936807a28b16-ecs","migrationVersion":{"visualization":"7.14.0"},"references":[{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"}],"type":"visualization","updated_at":"2021-08-04T16:35:57.797Z","version":"WzQ5NjcsMV0="}
{"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"language\":\"kuery\",\"query\":\"\"}}"},"savedSearchRefName":"search_0","title":"Exe Name Tag Cloud [Auditbeat Auditd] ECS","uiStateJSON":"{}","version":1,"visState":"{\"aggs\":[{\"enabled\":true,\"id\":\"1\",\"params\":{},\"schema\":\"metric\",\"type\":\"count\"},{\"enabled\":true,\"id\":\"2\",\"params\":{\"field\":\"process.executable\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":10},\"schema\":\"segment\",\"type\":\"terms\"}],\"params\":{\"maxFontSize\":45,\"minFontSize\":14,\"orientation\":\"single\",\"scale\":\"linear\",\"palette\":{\"type\":\"palette\",\"name\":\"kibana_palette\"}},\"title\":\"Exe Name Tag Cloud [Auditbeat Auditd] ECS\",\"type\":\"tagcloud\"}"},"coreMigrationVersion":"8.0.0","id":"2efac370-c1ca-11e7-8995-936807a28b16-ecs","migrationVersion":{"visualization":"7.14.0"},"references":[{"id":"d382f5b0-c1c6-11e7-8995-936807a28b16-ecs","name":"search_0","type":"search"}],"type":"visualization","updated_at":"2021-08-04T16:35:57.797Z","version":"WzQ5NjgsMV0="}
{"attributes":{"description":"Overview of kernel executions","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"highlightAll\":true,\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"version\":true}"},"optionsJSON":"{\"darkTheme\": false, \"useMargins\": false}","panelsJSON":"[{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"w\":16,\"h\":12,\"x\":16,\"y\":0,\"i\":\"1\"},\"panelIndex\":\"1\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_1\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"w\":16,\"h\":12,\"x\":32,\"y\":0,\"i\":\"3\"},\"panelIndex\":\"3\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_3\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"w\":16,\"h\":12,\"x\":0,\"y\":0,\"i\":\"5\"},\"panelIndex\":\"5\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_5\"},{\"version\":\"7.3.0\",\"type\":\"search\",\"gridData\":{\"w\":48,\"h\":20,\"x\":0,\"y\":12,\"i\":\"6\"},\"panelIndex\":\"6\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_6\"}]","timeRestore":false,"title":"[Auditbeat Auditd] Executions ECS","version":1},"coreMigrationVersion":"8.0.0","id":"7de391b0-c1ca-11e7-8995-936807a28b16-ecs","migrationVersion":{"dashboard":"7.14.0"},"references":[{"id":"20a8e8d0-c1c8-11e7-8995-936807a28b16-ecs","name":"1:panel_1","type":"visualization"},{"id":"f81a6de0-c1c1-11e7-8995-936807a28b16-ecs","name":"3:panel_3","type":"visualization"},{"id":"2efac370-c1ca-11e7-8995-936807a28b16-ecs","name":"5:panel_5","type":"visualization"},{"id":"d382f5b0-c1c6-11e7-8995-936807a28b16-ecs","name":"6:panel_6","type":"search"}],"type":"dashboard","updated_at":"2021-08-04T16:35:57.797Z","version":"WzQ5NzAsMV0="}
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
{"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{}"},"title":"Event Actions [Auditbeat Auditd] ECS","uiStateJSON":"{}","version":1,"visState":"{\"aggs\":[],\"params\":{\"axis_formatter\":\"number\",\"axis_position\":\"left\",\"background_color_rules\":[{\"id\":\"58c95a20-c1bd-11e7-938f-ab0645b6c431\"}],\"bar_color_rules\":[{\"id\":\"5bfc71a0-c1bd-11e7-938f-ab0645b6c431\"}],\"filter\":{\"query\":\"event.module:auditd\",\"language\":\"lucene\"},\"gauge_color_rules\":[{\"id\":\"5d20a650-c1bd-11e7-938f-ab0645b6c431\"}],\"gauge_inner_width\":10,\"gauge_style\":\"half\",\"gauge_width\":10,\"id\":\"61ca57f0-469d-11e7-af02-69e470af7417\",\"index_pattern\":\"auditbeat-*\",\"interval\":\"auto\",\"legend_position\":\"left\",\"series\":[{\"axis_position\":\"right\",\"chart_type\":\"line\",\"color\":\"#68BC00\",\"fill\":0.5,\"formatter\":\"number\",\"id\":\"61ca57f1-469d-11e7-af02-69e470af7417\",\"label\":\"Actions\",\"line_width\":1,\"metrics\":[{\"id\":\"6b9fb2d0-c1bc-11e7-938f-ab0645b6c431\",\"type\":\"count\"}],\"point_size\":1,\"seperate_axis\":0,\"split_mode\":\"terms\",\"stacked\":\"none\",\"terms_field\":\"event.action\",\"split_color_mode\":\"gradient\"}],\"show_grid\":1,\"show_legend\":1,\"time_field\":\"@timestamp\",\"type\":\"timeseries\",\"use_kibana_indexes\":false},\"title\":\"Event Actions [Auditbeat Auditd] ECS\",\"type\":\"metrics\"}"},"coreMigrationVersion":"8.0.0","id":"97680df0-c1c0-11e7-8995-936807a28b16-ecs","migrationVersion":{"visualization":"7.14.0"},"references":[],"type":"visualization","updated_at":"2021-08-04T16:35:58.815Z","version":"WzQ5NzEsMV0="}
{"attributes":{"columns":["agent.name","auditd.summary.actor.primary","auditd.summary.actor.secondary","event.action","auditd.summary.object.type","auditd.summary.object.primary","auditd.summary.object.secondary","auditd.summary.how","auditd.result"],"description":"","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[{\"$state\":{\"store\":\"appState\"},\"meta\":{\"alias\":null,\"disabled\":false,\"key\":\"event.module\",\"negate\":false,\"params\":{\"query\":\"auditd\",\"type\":\"phrase\"},\"type\":\"phrase\",\"value\":\"auditd\",\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index\"},\"query\":{\"match\":{\"event.module\":{\"query\":\"auditd\",\"type\":\"phrase\"}}}}],\"highlightAll\":true,\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"version\":true,\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"sort":[["@timestamp","desc"]],"title":"Audit Event Table [Auditbeat Auditd] ECS","version":1},"coreMigrationVersion":"8.0.0","id":"0f10c430-c1c3-11e7-8995-936807a28b16-ecs","migrationVersion":{"search":"7.9.3"},"references":[{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"},{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index","type":"index-pattern"}],"type":"search","updated_at":"2021-08-04T16:35:58.815Z","version":"WzQ5NzMsMV0="}
{"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"savedSearchRefName":"search_0","title":"Event Categories [Auditbeat Auditd] ECS","uiStateJSON":"{}","version":1,"visState":"{\"aggs\":[{\"enabled\":true,\"id\":\"1\",\"params\":{},\"schema\":\"metric\",\"type\":\"count\"},{\"enabled\":true,\"id\":\"2\",\"params\":{\"customLabel\":\"Category\",\"field\":\"event.category\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":5},\"schema\":\"segment\",\"type\":\"terms\"},{\"enabled\":true,\"id\":\"3\",\"params\":{\"customLabel\":\"Action\",\"field\":\"event.action\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":20},\"schema\":\"segment\",\"type\":\"terms\"}],\"params\":{\"addLegend\":true,\"addTooltip\":true,\"isDonut\":true,\"legendPosition\":\"right\",\"type\":\"pie\",\"palette\":{\"type\":\"palette\",\"name\":\"kibana_palette\"},\"distinctColors\":true},\"title\":\"Event Categories [Auditbeat Auditd] ECS\",\"type\":\"pie\"}"},"coreMigrationVersion":"8.0.0","id":"08679220-c25a-11e7-8692-232bd1143e8a-ecs","migrationVersion":{"visualization":"7.14.0"},"references":[{"id":"auditbeat-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"},{"id":"0f10c430-c1c3-11e7-8995-936807a28b16-ecs","name":"search_0","type":"search"}],"type":"visualization","updated_at":"2021-08-04T16:35:58.815Z","version":"WzQ5NzIsMV0="}
{"attributes":{"description":"Summary of Linux kernel audit events.","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"highlightAll\":true,\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"version\":true}"},"optionsJSON":"{\"darkTheme\": false, \"useMargins\": false}","panelsJSON":"[{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"w\":28,\"h\":12,\"x\":0,\"y\":0,\"i\":\"1\"},\"panelIndex\":\"1\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_1\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"w\":20,\"h\":12,\"x\":28,\"y\":0,\"i\":\"4\"},\"panelIndex\":\"4\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_4\"},{\"version\":\"7.3.0\",\"type\":\"search\",\"gridData\":{\"w\":48,\"h\":20,\"x\":0,\"y\":12,\"i\":\"5\"},\"panelIndex\":\"5\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_5\"}]","timeRestore":false,"title":"[Auditbeat Auditd] Overview ECS","version":1},"coreMigrationVersion":"8.0.0","id":"c0ac2c00-c1c0-11e7-8995-936807a28b16-ecs","migrationVersion":{"dashboard":"7.14.0"},"references":[{"id":"97680df0-c1c0-11e7-8995-936807a28b16-ecs","name":"1:panel_1","type":"visualization"},{"id":"08679220-c25a-11e7-8692-232bd1143e8a-ecs","name":"4:panel_4","type":"visualization"},{"id":"0f10c430-c1c3-11e7-8995-936807a28b16-ecs","name":"5:panel_5","type":"search"}],"type":"dashboard","updated_at":"2021-08-04T16:35:58.815Z","version":"WzQ5NzQsMV0="}
Loading

0 comments on commit 2d44a6c

Please sign in to comment.