mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-08 18:22:47 +01:00
remove role conditional from all panel queiries
This commit is contained in:
@@ -108,12 +108,6 @@
|
|||||||
"key": "cpu",
|
"key": "cpu",
|
||||||
"operator": "=",
|
"operator": "=",
|
||||||
"value": "cpu-total"
|
"value": "cpu-total"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(blocked) as blocked FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(blocked) as blocked FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(paging) as paging FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(paging) as paging FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(running) as running FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(running) as running FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(sleeping) as sleeping FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(sleeping) as sleeping FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(stopped) as stopped FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(stopped) as stopped FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(unknown) as unknown FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(unknown) as unknown FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,7 +44,7 @@
|
|||||||
}
|
}
|
||||||
]
|
]
|
||||||
],
|
],
|
||||||
"query": "SELECT mean(zombies) as zombies FROM \"processes\" WHERE (host =~ /$servername$/ AND role =~ /$role$/) AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
"query": "SELECT mean(zombies) as zombies FROM \"processes\" WHERE host =~ /$servername$/ AND $timeFilter GROUP BY time($__interval), host, role ORDER BY asc",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"alias": "$tag_host $tag_role"
|
"alias": "$tag_host $tag_role"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -96,12 +96,6 @@
|
|||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"condition": "AND",
|
"condition": "AND",
|
||||||
"key": "path",
|
"key": "path",
|
||||||
|
|||||||
@@ -96,12 +96,6 @@
|
|||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"condition": "AND",
|
"condition": "AND",
|
||||||
"key": "path",
|
"key": "path",
|
||||||
|
|||||||
@@ -26,12 +26,6 @@
|
|||||||
"key": "cpu",
|
"key": "cpu",
|
||||||
"operator": "=",
|
"operator": "=",
|
||||||
"value": "cpu-total"
|
"value": "cpu-total"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"groupBy": [
|
"groupBy": [
|
||||||
|
|||||||
@@ -65,7 +65,7 @@
|
|||||||
],
|
],
|
||||||
"measurement": "cpu",
|
"measurement": "cpu",
|
||||||
"policy": "default",
|
"policy": "default",
|
||||||
"query": "SELECT non_negative_derivative(mean(\"usage_iowait\"), 1s) FROM \"cpu\" WHERE (host =~ /$servername$/ AND role =~ /$role$/ AND \"cpu\" = 'cpu-total') AND $timeFilter GROUP BY time($interval) fill(null)",
|
"query": "SELECT non_negative_derivative(mean(\"usage_iowait\"), 1s) FROM \"cpu\" WHERE (host =~ /$servername$/ AND \"cpu\" = 'cpu-total') AND $timeFilter GROUP BY time($interval) fill(null)",
|
||||||
"rawQuery": false,
|
"rawQuery": false,
|
||||||
"refId": "A",
|
"refId": "A",
|
||||||
"resultFormat": "time_series",
|
"resultFormat": "time_series",
|
||||||
|
|||||||
@@ -65,7 +65,7 @@
|
|||||||
],
|
],
|
||||||
"orderByTime": "ASC",
|
"orderByTime": "ASC",
|
||||||
"policy": "default",
|
"policy": "default",
|
||||||
"query": "SELECT non_negative_derivative(mean(drop_in), 1s) as \"in\" FROM \"net\" WHERE host =~ /$servername/ AND interface =~ /$manint/ AND role =~ /$role/ AND $timeFilter GROUP BY time($__interval), host,role fill(none)",
|
"query": "SELECT non_negative_derivative(mean(drop_in), 1s) as \"in\" FROM \"net\" WHERE host =~ /$servername/ AND interface =~ /$manint/ AND $timeFilter GROUP BY time($__interval), host,role fill(none)",
|
||||||
"queryType": "randomWalk",
|
"queryType": "randomWalk",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"refId": "A",
|
"refId": "A",
|
||||||
|
|||||||
@@ -66,7 +66,7 @@
|
|||||||
"hide": false,
|
"hide": false,
|
||||||
"orderByTime": "ASC",
|
"orderByTime": "ASC",
|
||||||
"policy": "default",
|
"policy": "default",
|
||||||
"query": "SELECT non_negative_derivative(mean(drop_out), 1s) as \"out\" FROM \"net\" WHERE host =~ /$servername/ AND interface =~ /$manint/ AND role =~ /$role/ AND $timeFilter GROUP BY time($__interval), host,role fill(none)",
|
"query": "SELECT non_negative_derivative(mean(drop_out), 1s) as \"out\" FROM \"net\" WHERE host =~ /$servername/ AND interface =~ /$manint/ AND $timeFilter GROUP BY time($__interval), host,role fill(none)",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"refId": "B",
|
"refId": "B",
|
||||||
"resultFormat": "time_series",
|
"resultFormat": "time_series",
|
||||||
|
|||||||
@@ -122,12 +122,6 @@
|
|||||||
"key": "interface",
|
"key": "interface",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$manint$/"
|
"value": "/^$manint$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -120,12 +120,6 @@
|
|||||||
"key": "interface",
|
"key": "interface",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$manint$/"
|
"value": "/^$manint$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,12 +20,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"groupBy": [
|
"groupBy": [
|
||||||
|
|||||||
@@ -63,7 +63,7 @@
|
|||||||
],
|
],
|
||||||
"orderByTime": "ASC",
|
"orderByTime": "ASC",
|
||||||
"policy": "default",
|
"policy": "default",
|
||||||
"query": "SELECT non_negative_derivative(mean(drop_in), 1s) as \"in\" FROM \"net\" WHERE host =~ /$servername/ AND interface =~ /$monint/ AND role =~ /$role/ AND $timeFilter GROUP BY time($__interval), host,role fill(none)",
|
"query": "SELECT non_negative_derivative(mean(drop_in), 1s) as \"in\" FROM \"net\" WHERE host =~ /$servername/ AND interface =~ /$monint/ AND $timeFilter GROUP BY time($__interval), host,role fill(none)",
|
||||||
"queryType": "randomWalk",
|
"queryType": "randomWalk",
|
||||||
"rawQuery": true,
|
"rawQuery": true,
|
||||||
"refId": "A",
|
"refId": "A",
|
||||||
|
|||||||
@@ -122,12 +122,6 @@
|
|||||||
"key": "interface",
|
"key": "interface",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$monint$/"
|
"value": "/^$monint$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -106,12 +106,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -169,12 +163,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -112,12 +112,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -181,12 +175,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,12 +20,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"groupBy": [
|
"groupBy": [
|
||||||
|
|||||||
@@ -20,12 +20,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"groupBy": [
|
"groupBy": [
|
||||||
|
|||||||
@@ -76,7 +76,7 @@
|
|||||||
"measurement": "docker_container_status",
|
"measurement": "docker_container_status",
|
||||||
"orderByTime": "ASC",
|
"orderByTime": "ASC",
|
||||||
"policy": "default",
|
"policy": "default",
|
||||||
"query": "SELECT last(\"uptime_ns\") FROM \"docker_container_status\" WHERE (\"host\" =~ /^$servername$/ AND \"container_name\" =~ /^$containers$/ AND \"role\" =~ /^$role$/) AND $timeFilter GROUP BY time($__interval), \"container_name\", \"host\", \"role\" fill(null)",
|
"query": "SELECT last(\"uptime_ns\") FROM \"docker_container_status\" WHERE (\"host\" =~ /^$servername$/ AND \"container_name\" =~ /^$containers$/) AND $timeFilter GROUP BY time($__interval), \"container_name\", \"host\", \"role\" fill(null)",
|
||||||
"queryType": "randomWalk",
|
"queryType": "randomWalk",
|
||||||
"rawQuery": false,
|
"rawQuery": false,
|
||||||
"refId": "A",
|
"refId": "A",
|
||||||
@@ -106,12 +106,6 @@
|
|||||||
"key": "container_name",
|
"key": "container_name",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$containers$/"
|
"value": "/^$containers$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"slimit": "",
|
"slimit": "",
|
||||||
|
|||||||
@@ -112,12 +112,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -181,12 +175,6 @@
|
|||||||
"key": "host",
|
"key": "host",
|
||||||
"operator": "=~",
|
"operator": "=~",
|
||||||
"value": "/^$servername$/"
|
"value": "/^$servername$/"
|
||||||
},
|
|
||||||
{
|
|
||||||
"condition": "AND",
|
|
||||||
"key": "role",
|
|
||||||
"operator": "=~",
|
|
||||||
"value": "/^$role$/"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user