diff --git a/doc/ElasticStackImport/15-HayabusaDashboard-StackManagement.png b/doc/ElasticStackImport/15-HayabusaDashboard-StackManagement.png new file mode 100644 index 00000000..9ddc3f61 Binary files /dev/null and b/doc/ElasticStackImport/15-HayabusaDashboard-StackManagement.png differ diff --git a/doc/ElasticStackImport/16-HayabusaDashboard-Import.png b/doc/ElasticStackImport/16-HayabusaDashboard-Import.png new file mode 100644 index 00000000..c43c3460 Binary files /dev/null and b/doc/ElasticStackImport/16-HayabusaDashboard-Import.png differ diff --git a/doc/ElasticStackImport/17-HayabusaDashboard-1.png b/doc/ElasticStackImport/17-HayabusaDashboard-1.png new file mode 100644 index 00000000..5f5f2896 Binary files /dev/null and b/doc/ElasticStackImport/17-HayabusaDashboard-1.png differ diff --git a/doc/ElasticStackImport/18-HayabusaDashboard-2.png b/doc/ElasticStackImport/18-HayabusaDashboard-2.png new file mode 100644 index 00000000..0a5cee5e Binary files /dev/null and b/doc/ElasticStackImport/18-HayabusaDashboard-2.png differ diff --git a/doc/ElasticStackImport/ElasticStackImport-English.md b/doc/ElasticStackImport/ElasticStackImport-English.md index 44b9d4ec..3a74dabc 100644 --- a/doc/ElasticStackImport/ElasticStackImport-English.md +++ b/doc/ElasticStackImport/ElasticStackImport-English.md @@ -79,13 +79,7 @@ The default Discover view should look similar to this: ![Discover View](10-Discover.png) -You can get an overview of when the events happened and frequency of events by looking at the histogram at top. You can filter with KQL to search for certain events and alerts. For example: - * `Level: "critical"`: Just show critical alerts. - * `Level: "critical" or Level: "high"`: Show high and critical alerts. - * `NOT Level:info`: Do not show informational events, only alerts. - * `*LatMov*`: Show events and alerts related to lateral movement. - * `"Password Spray"`: Only show specific attacks such as "Password Spray". - * `"LID: 0x8724ead"`: Display all activity associated with Logon ID 0x8724ead. +You can get an overview of when the events happened and frequency of events by looking at the histogram at top. On the left side sidebar, you can select with fields you want to display in columns: @@ -99,6 +93,38 @@ Your Discover view should now look like this: ![Discover With Columns](14-DicoverWithColumns.png) +You can filter with KQL to search for certain events and alerts. For example: + * `Level: "critical"`: Just show critical alerts. + * `Level: "critical" or Level: "high"`: Show high and critical alerts. + * `NOT Level:info`: Do not show informational events, only alerts. + * `*LatMov*`: Show events and alerts related to lateral movement. + * `"Password Spray"`: Only show specific attacks such as "Password Spray". + * `"LID: 0x8724ead"`: Display all activity associated with Logon ID 0x8724ead. +## Hayabusa Dashboard -https://qiita.com/kzzzzo2/items/ead8ccc77b7609143749 \ No newline at end of file +We have exported a simple Hayabusa Dashboard in JSON to download [here](https://github.com/Yamato-Security/hayabusa/blob/main/doc/ElasticStackImport/HayabusaDashboard.ndjson) + +To import the dashboard, open the left sidebar and click `Stack Management` under `Management`. + +![Stack Management](15-HayabusaDashboard-StackManagement.png) + +After clicking `Saved Objects`, please click `Import` in the upper right-hand corner and import the Hayabusa Dashboard JSON file you downloaded. + +![Import Dashboard](16-HayabusaDashboard-Import.png) + +You should now be able to use the dashboard shown below: + +![Hayabusa Dashboard-1](17-HayabusaDashboard-1.png) + +![Hayabussa Dashboard-2](18-HayabusaDashboard-2.png) + +## Future Plans + +We plan on creating Hayabusa logstash parsers and dashboard pre-built for SOF-ELK so that all you will need to do is copy the CSV results file to a directory in order to ingest the logs. + +## Acknowledgements + +Much of this documentation was taken from the blog write-up in Japanese from @kzzzzo2 [here](https://qiita.com/kzzzzo2/items/ead8ccc77b7609143749). + +Many thanks to @kzzzzo2! \ No newline at end of file diff --git a/doc/ElasticStackImport/HayabusaDashboard.ndjson b/doc/ElasticStackImport/HayabusaDashboard.ndjson new file mode 100644 index 00000000..262a8615 --- /dev/null +++ b/doc/ElasticStackImport/HayabusaDashboard.ndjson @@ -0,0 +1,4 @@ +{"attributes":{"fieldAttrs":"{\"Computer\":{\"count\":3},\"Details\":{\"count\":3},\"EventID\":{\"count\":3},\"Level\":{\"count\":4},\"MitreAttack\":{\"count\":3},\"RuleTitle\":{\"count\":3}}","fields":"[]","runtimeFieldMap":"{}","timeFieldName":"@timestamp","title":"evtxlogs-hayabusa","typeMeta":"{}"},"coreMigrationVersion":"7.17.1","id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","migrationVersion":{"index-pattern":"7.11.0"},"references":[],"type":"index-pattern","updated_at":"2022-04-15T00:28:01.828Z","version":"WzExNjAsM10="} +{"attributes":{"columns":["Computer","EventID","Level","MitreAttack","RuleTitle","Details"],"description":"","grid":{},"hideChart":false,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filter\":[],\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"sort":[["@timestamp","desc"]],"title":"Hayabusa Discover"},"coreMigrationVersion":"7.17.1","id":"d0e3ad60-bc6a-11ec-b4f7-8347b07fe863","migrationVersion":{"search":"7.9.3"},"references":[{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"}],"type":"search","updated_at":"2022-04-15T03:19:09.878Z","version":"WzE2NzAsM10="} +{"attributes":{"description":"","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filter\":[]}"},"optionsJSON":"{\"useMargins\":true,\"syncColors\":false,\"hidePanelTitles\":false}","panelsJSON":"[{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":0,\"y\":0,\"w\":12,\"h\":17,\"i\":\"1af33197-eac8-463d-ae7e-3b8a89568122\"},\"panelIndex\":\"1af33197-eac8-463d-ae7e-3b8a89568122\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Risk Level\",\"description\":\"\",\"visualizationType\":\"lnsPie\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-41bca02b-ab6b-4422-9761-edadaf1e95ce\"}],\"state\":{\"visualization\":{\"shape\":\"pie\",\"layers\":[{\"layerId\":\"41bca02b-ab6b-4422-9761-edadaf1e95ce\",\"groups\":[\"28876efd-84a4-4ebb-9d29-998b1c6d53f6\"],\"metric\":\"4c54f46f-5df6-43a6-8200-10ae8a112f44\",\"numberDisplay\":\"percent\",\"categoryDisplay\":\"default\",\"legendDisplay\":\"default\",\"nestedLegend\":false,\"layerType\":\"data\"}]},\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"41bca02b-ab6b-4422-9761-edadaf1e95ce\":{\"columns\":{\"28876efd-84a4-4ebb-9d29-998b1c6d53f6\":{\"label\":\"Top values of Level\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"Level\",\"isBucketed\":true,\"params\":{\"size\":5,\"orderBy\":{\"type\":\"column\",\"columnId\":\"4c54f46f-5df6-43a6-8200-10ae8a112f44\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"4c54f46f-5df6-43a6-8200-10ae8a112f44\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"28876efd-84a4-4ebb-9d29-998b1c6d53f6\",\"4c54f46f-5df6-43a6-8200-10ae8a112f44\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":12,\"y\":0,\"w\":11,\"h\":17,\"i\":\"738fb5e1-834b-465e-b6ba-4de422c663d9\"},\"panelIndex\":\"738fb5e1-834b-465e-b6ba-4de422c663d9\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Detection Rule\",\"description\":\"\",\"visualizationType\":\"lnsPie\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-aaacd848-cb93-46e9-acf1-070f6b39dace\"}],\"state\":{\"visualization\":{\"shape\":\"donut\",\"layers\":[{\"layerId\":\"aaacd848-cb93-46e9-acf1-070f6b39dace\",\"groups\":[\"7eae6d74-b193-42e1-b5c4-c5fb6c7deb12\"],\"metric\":\"bf28ae0f-2ad8-452b-94d7-6fbf385228ee\",\"numberDisplay\":\"percent\",\"categoryDisplay\":\"default\",\"legendDisplay\":\"default\",\"nestedLegend\":false,\"layerType\":\"data\"}]},\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"aaacd848-cb93-46e9-acf1-070f6b39dace\":{\"columns\":{\"7eae6d74-b193-42e1-b5c4-c5fb6c7deb12\":{\"label\":\"Top values of RuleTitle\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"RuleTitle\",\"isBucketed\":true,\"params\":{\"size\":5,\"orderBy\":{\"type\":\"column\",\"columnId\":\"bf28ae0f-2ad8-452b-94d7-6fbf385228ee\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"bf28ae0f-2ad8-452b-94d7-6fbf385228ee\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"7eae6d74-b193-42e1-b5c4-c5fb6c7deb12\",\"bf28ae0f-2ad8-452b-94d7-6fbf385228ee\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":23,\"y\":0,\"w\":11,\"h\":17,\"i\":\"54a171e3-5440-4171-8991-e07417a3e2cd\"},\"panelIndex\":\"54a171e3-5440-4171-8991-e07417a3e2cd\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Event ID\",\"description\":\"\",\"visualizationType\":\"lnsPie\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-4dd9733a-b2c3-449d-a7b8-78bf2f7621ab\"}],\"state\":{\"visualization\":{\"shape\":\"donut\",\"layers\":[{\"layerId\":\"4dd9733a-b2c3-449d-a7b8-78bf2f7621ab\",\"groups\":[\"090a1665-f0e8-4450-bfd0-d76eb9e9e7fd\"],\"metric\":\"8459d081-19df-43db-a545-120ed19db287\",\"numberDisplay\":\"percent\",\"categoryDisplay\":\"default\",\"legendDisplay\":\"default\",\"nestedLegend\":false,\"layerType\":\"data\"}]},\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"4dd9733a-b2c3-449d-a7b8-78bf2f7621ab\":{\"columns\":{\"090a1665-f0e8-4450-bfd0-d76eb9e9e7fd\":{\"label\":\"Top values of EventID\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"EventID\",\"isBucketed\":true,\"params\":{\"size\":5,\"orderBy\":{\"type\":\"column\",\"columnId\":\"8459d081-19df-43db-a545-120ed19db287\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"8459d081-19df-43db-a545-120ed19db287\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"090a1665-f0e8-4450-bfd0-d76eb9e9e7fd\",\"8459d081-19df-43db-a545-120ed19db287\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":34,\"y\":0,\"w\":11,\"h\":17,\"i\":\"2d258460-f836-4b9b-9e32-6bce96b0851b\"},\"panelIndex\":\"2d258460-f836-4b9b-9e32-6bce96b0851b\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Computer Names\",\"description\":\"\",\"visualizationType\":\"lnsDatatable\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-a2f6321e-66ca-44f9-b1b5-a64203a0333f\"}],\"state\":{\"visualization\":{\"columns\":[{\"isTransposed\":false,\"columnId\":\"abf4669d-ca1a-4e29-bf6b-580c0155bc9a\"},{\"isTransposed\":false,\"columnId\":\"18cef55c-e7fa-4178-8e2f-9708acbe4254\"}],\"layerId\":\"a2f6321e-66ca-44f9-b1b5-a64203a0333f\",\"layerType\":\"data\"},\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"a2f6321e-66ca-44f9-b1b5-a64203a0333f\":{\"columns\":{\"abf4669d-ca1a-4e29-bf6b-580c0155bc9a\":{\"label\":\"Top values of Computer\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"Computer\",\"isBucketed\":true,\"params\":{\"size\":10,\"orderBy\":{\"type\":\"column\",\"columnId\":\"18cef55c-e7fa-4178-8e2f-9708acbe4254\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"18cef55c-e7fa-4178-8e2f-9708acbe4254\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"abf4669d-ca1a-4e29-bf6b-580c0155bc9a\",\"18cef55c-e7fa-4178-8e2f-9708acbe4254\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":0,\"y\":17,\"w\":45,\"h\":13,\"i\":\"7c5f7c70-7d78-4d68-803c-4222b5c5e5c0\"},\"panelIndex\":\"7c5f7c70-7d78-4d68-803c-4222b5c5e5c0\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Risk Over Time\",\"description\":\"\",\"visualizationType\":\"lnsXY\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-75d03fdf-bd36-47d9-851c-a78cacecb37f\"}],\"state\":{\"visualization\":{\"legend\":{\"isVisible\":true,\"position\":\"right\"},\"valueLabels\":\"hide\",\"fittingFunction\":\"None\",\"yLeftExtent\":{\"mode\":\"full\"},\"yRightExtent\":{\"mode\":\"full\"},\"axisTitlesVisibilitySettings\":{\"x\":true,\"yLeft\":true,\"yRight\":true},\"tickLabelsVisibilitySettings\":{\"x\":true,\"yLeft\":true,\"yRight\":true},\"labelsOrientation\":{\"x\":0,\"yLeft\":0,\"yRight\":0},\"gridlinesVisibilitySettings\":{\"x\":true,\"yLeft\":true,\"yRight\":true},\"preferredSeriesType\":\"bar_stacked\",\"layers\":[{\"layerId\":\"75d03fdf-bd36-47d9-851c-a78cacecb37f\",\"accessors\":[\"c5277819-371a-4f5a-97e4-df763b276b1f\"],\"position\":\"top\",\"seriesType\":\"bar_stacked\",\"showGridlines\":false,\"layerType\":\"data\",\"xAccessor\":\"4c31cd0a-08e8-4266-910d-14717b06ac2f\",\"splitAccessor\":\"8ebfda45-9671-4fb6-a253-06b90d989ae3\"}]},\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"75d03fdf-bd36-47d9-851c-a78cacecb37f\":{\"columns\":{\"8ebfda45-9671-4fb6-a253-06b90d989ae3\":{\"label\":\"Top values of Level\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"Level\",\"isBucketed\":true,\"params\":{\"size\":5,\"orderBy\":{\"type\":\"column\",\"columnId\":\"c5277819-371a-4f5a-97e4-df763b276b1f\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"4c31cd0a-08e8-4266-910d-14717b06ac2f\":{\"label\":\"@timestamp\",\"dataType\":\"date\",\"operationType\":\"date_histogram\",\"sourceField\":\"@timestamp\",\"isBucketed\":true,\"scale\":\"interval\",\"params\":{\"interval\":\"auto\"}},\"c5277819-371a-4f5a-97e4-df763b276b1f\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"8ebfda45-9671-4fb6-a253-06b90d989ae3\",\"4c31cd0a-08e8-4266-910d-14717b06ac2f\",\"c5277819-371a-4f5a-97e4-df763b276b1f\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":0,\"y\":30,\"w\":20,\"h\":17,\"i\":\"d18ce65d-f280-4428-a6a7-6cebe812efd7\"},\"panelIndex\":\"d18ce65d-f280-4428-a6a7-6cebe812efd7\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Top 10 Alerts\",\"description\":\"\",\"visualizationType\":\"lnsDatatable\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-ad48706c-2160-4d2f-93e9-afba4411ac58\"}],\"state\":{\"visualization\":{\"columns\":[{\"isTransposed\":false,\"columnId\":\"841c01be-d9b7-4dba-a2b3-11f449677fac\"},{\"isTransposed\":false,\"columnId\":\"8448dbd4-ea47-435e-a197-6f17a6eae336\"},{\"columnId\":\"d815af3a-f2de-49cc-a5bf-742519a538e5\",\"isTransposed\":true}],\"layerId\":\"ad48706c-2160-4d2f-93e9-afba4411ac58\",\"layerType\":\"data\"},\"query\":{\"query\":\"\",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"ad48706c-2160-4d2f-93e9-afba4411ac58\":{\"columns\":{\"841c01be-d9b7-4dba-a2b3-11f449677fac\":{\"label\":\"Top values of RuleTitle\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"RuleTitle\",\"isBucketed\":true,\"params\":{\"size\":5,\"orderBy\":{\"type\":\"column\",\"columnId\":\"8448dbd4-ea47-435e-a197-6f17a6eae336\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"8448dbd4-ea47-435e-a197-6f17a6eae336\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"},\"d815af3a-f2de-49cc-a5bf-742519a538e5\":{\"label\":\"Top values of Level\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"Level\",\"isBucketed\":true,\"params\":{\"size\":5,\"orderBy\":{\"type\":\"column\",\"columnId\":\"8448dbd4-ea47-435e-a197-6f17a6eae336\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}}},\"columnOrder\":[\"d815af3a-f2de-49cc-a5bf-742519a538e5\",\"841c01be-d9b7-4dba-a2b3-11f449677fac\",\"8448dbd4-ea47-435e-a197-6f17a6eae336\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":20,\"y\":30,\"w\":13,\"h\":17,\"i\":\"7e2d20a9-16d4-4c02-9859-b6ac2798355d\"},\"panelIndex\":\"7e2d20a9-16d4-4c02-9859-b6ac2798355d\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Top 10 Critical Alerts\",\"description\":\"\",\"visualizationType\":\"lnsDatatable\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-bc8d7445-5f2c-4a8d-b771-1c19138bf11e\"}],\"state\":{\"visualization\":{\"columns\":[{\"isTransposed\":false,\"columnId\":\"aa763230-c5d1-43bc-8606-b58c20380b9f\"},{\"isTransposed\":false,\"columnId\":\"4ebf9bbd-1ac4-49a2-afab-e1122c99a8a1\"}],\"layerId\":\"bc8d7445-5f2c-4a8d-b771-1c19138bf11e\",\"layerType\":\"data\"},\"query\":{\"query\":\"Level:\\\"critical\\\" \",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"bc8d7445-5f2c-4a8d-b771-1c19138bf11e\":{\"columns\":{\"aa763230-c5d1-43bc-8606-b58c20380b9f\":{\"label\":\"Top values of RuleTitle\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"RuleTitle\",\"isBucketed\":true,\"params\":{\"size\":10,\"orderBy\":{\"type\":\"column\",\"columnId\":\"4ebf9bbd-1ac4-49a2-afab-e1122c99a8a1\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"4ebf9bbd-1ac4-49a2-afab-e1122c99a8a1\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"aa763230-c5d1-43bc-8606-b58c20380b9f\",\"4ebf9bbd-1ac4-49a2-afab-e1122c99a8a1\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"lens\",\"gridData\":{\"x\":33,\"y\":30,\"w\":12,\"h\":17,\"i\":\"721424a7-8543-445e-8b33-59666fc98f2a\"},\"panelIndex\":\"721424a7-8543-445e-8b33-59666fc98f2a\",\"embeddableConfig\":{\"attributes\":{\"title\":\"Top 10 High Alerts\",\"description\":\"\",\"visualizationType\":\"lnsDatatable\",\"type\":\"lens\",\"references\":[{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-current-indexpattern\"},{\"type\":\"index-pattern\",\"id\":\"8e85a670-bc4d-11ec-b4f7-8347b07fe863\",\"name\":\"indexpattern-datasource-layer-90df50b6-ceec-47d6-8609-a4cf7e6f7ec0\"}],\"state\":{\"visualization\":{\"columns\":[{\"isTransposed\":false,\"columnId\":\"eadb527b-9160-4fd2-9d4d-4059f4dd3a6b\"},{\"isTransposed\":false,\"columnId\":\"435bd7ff-9770-4bf6-9ce3-52469d1b8d24\"}],\"layerId\":\"90df50b6-ceec-47d6-8609-a4cf7e6f7ec0\",\"layerType\":\"data\"},\"query\":{\"query\":\"Level:\\\"high\\\" \",\"language\":\"kuery\"},\"filters\":[],\"datasourceStates\":{\"indexpattern\":{\"layers\":{\"90df50b6-ceec-47d6-8609-a4cf7e6f7ec0\":{\"columns\":{\"eadb527b-9160-4fd2-9d4d-4059f4dd3a6b\":{\"label\":\"Top values of RuleTitle\",\"dataType\":\"string\",\"operationType\":\"terms\",\"scale\":\"ordinal\",\"sourceField\":\"RuleTitle\",\"isBucketed\":true,\"params\":{\"size\":10,\"orderBy\":{\"type\":\"column\",\"columnId\":\"435bd7ff-9770-4bf6-9ce3-52469d1b8d24\"},\"orderDirection\":\"desc\",\"otherBucket\":true,\"missingBucket\":false}},\"435bd7ff-9770-4bf6-9ce3-52469d1b8d24\":{\"label\":\"Count of records\",\"dataType\":\"number\",\"operationType\":\"count\",\"isBucketed\":false,\"scale\":\"ratio\",\"sourceField\":\"Records\"}},\"columnOrder\":[\"eadb527b-9160-4fd2-9d4d-4059f4dd3a6b\",\"435bd7ff-9770-4bf6-9ce3-52469d1b8d24\"],\"incompleteColumns\":{}}}}}}},\"enhancements\":{}}},{\"version\":\"7.17.1\",\"type\":\"search\",\"gridData\":{\"x\":0,\"y\":47,\"w\":45,\"h\":30,\"i\":\"dda19205-5619-4f11-b6ec-e33c86cfb330\"},\"panelIndex\":\"dda19205-5619-4f11-b6ec-e33c86cfb330\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_dda19205-5619-4f11-b6ec-e33c86cfb330\"}]","timeRestore":false,"title":"Hayabusa Dashboard","version":1},"coreMigrationVersion":"7.17.1","id":"332ec800-bc67-11ec-b4f7-8347b07fe863","migrationVersion":{"dashboard":"7.17.0"},"references":[{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"1af33197-eac8-463d-ae7e-3b8a89568122:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"1af33197-eac8-463d-ae7e-3b8a89568122:indexpattern-datasource-layer-41bca02b-ab6b-4422-9761-edadaf1e95ce","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"738fb5e1-834b-465e-b6ba-4de422c663d9:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"738fb5e1-834b-465e-b6ba-4de422c663d9:indexpattern-datasource-layer-aaacd848-cb93-46e9-acf1-070f6b39dace","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"54a171e3-5440-4171-8991-e07417a3e2cd:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"54a171e3-5440-4171-8991-e07417a3e2cd:indexpattern-datasource-layer-4dd9733a-b2c3-449d-a7b8-78bf2f7621ab","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"2d258460-f836-4b9b-9e32-6bce96b0851b:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"2d258460-f836-4b9b-9e32-6bce96b0851b:indexpattern-datasource-layer-a2f6321e-66ca-44f9-b1b5-a64203a0333f","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"7c5f7c70-7d78-4d68-803c-4222b5c5e5c0:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"7c5f7c70-7d78-4d68-803c-4222b5c5e5c0:indexpattern-datasource-layer-75d03fdf-bd36-47d9-851c-a78cacecb37f","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"d18ce65d-f280-4428-a6a7-6cebe812efd7:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"d18ce65d-f280-4428-a6a7-6cebe812efd7:indexpattern-datasource-layer-ad48706c-2160-4d2f-93e9-afba4411ac58","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"7e2d20a9-16d4-4c02-9859-b6ac2798355d:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"7e2d20a9-16d4-4c02-9859-b6ac2798355d:indexpattern-datasource-layer-bc8d7445-5f2c-4a8d-b771-1c19138bf11e","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"721424a7-8543-445e-8b33-59666fc98f2a:indexpattern-datasource-current-indexpattern","type":"index-pattern"},{"id":"8e85a670-bc4d-11ec-b4f7-8347b07fe863","name":"721424a7-8543-445e-8b33-59666fc98f2a:indexpattern-datasource-layer-90df50b6-ceec-47d6-8609-a4cf7e6f7ec0","type":"index-pattern"},{"id":"d0e3ad60-bc6a-11ec-b4f7-8347b07fe863","name":"dda19205-5619-4f11-b6ec-e33c86cfb330:panel_dda19205-5619-4f11-b6ec-e33c86cfb330","type":"search"}],"type":"dashboard","updated_at":"2022-04-15T03:25:13.683Z","version":"WzE3MzQsM10="} +{"excludedObjects":[],"excludedObjectsCount":0,"exportedCount":3,"missingRefCount":0,"missingReferences":[]} \ No newline at end of file