diff --git a/salt/kibana/files/saved_objects.ndjson b/salt/kibana/files/saved_objects.ndjson index 215b584eb..9193530b3 100644 --- a/salt/kibana/files/saved_objects.ndjson +++ b/salt/kibana/files/saved_objects.ndjson @@ -427,7 +427,7 @@ {"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[]}"},"savedSearchRefName":"search_0","title":"DCE/RPC - Operation","uiStateJSON":"{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}","version":1,"visState":"{\"title\":\"DCE/RPC - Operation\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\",\"showToolbar\":true},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"operation.keyword\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Operation\"}}],\"listeners\":{}}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"86107960-3af3-11e7-a83b-b1b4da7d15f4","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"913c5b80-3aab-11e7-8b17-0d8709b02c80","name":"search_0","type":"search"}],"sort":[1688135089819,5347],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNDgsMV0="} {"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[]}"},"savedSearchRefName":"search_0","title":"RFB - Authentication Status (Donut Chart)","uiStateJSON":"{}","version":1,"visState":"{\"title\":\"RFB - Authentication Status (Donut Chart)\",\"type\":\"pie\",\"params\":{\"addTooltip\":true,\"legendPosition\":\"right\",\"isDonut\":true,\"palette\":{\"type\":\"palette\",\"name\":\"kibana_palette\"},\"distinctColors\":true,\"legendDisplay\":\"show\",\"legendSize\":\"auto\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"auth.keyword\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"Authentication Status\"}}],\"listeners\":{}}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"869e3030-371e-11e7-90f8-87842d5eedc9","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"8ba53710-342e-11e7-9e93-53b62e1857b2","name":"search_0","type":"search"}],"sort":[1688135089819,5349],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNDksMV0="} {"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"title":"Security Onion - Modbus - Exception","uiStateJSON":"{}","version":1,"visState":"{\"title\":\"Security Onion - Modbus - Exception\",\"type\":\"pie\",\"params\":{\"type\":\"pie\",\"addTooltip\":true,\"legendPosition\":\"right\",\"isDonut\":true,\"labels\":{\"show\":false,\"values\":true,\"last_level\":true,\"truncate\":100},\"dimensions\":{\"metric\":{\"accessor\":1,\"format\":{\"id\":\"number\"},\"params\":{},\"label\":\"Count\",\"aggType\":\"count\"},\"buckets\":[{\"accessor\":0,\"format\":{\"id\":\"terms\",\"params\":{\"id\":\"string\",\"otherBucketLabel\":\"Other\",\"missingBucketLabel\":\"Missing\",\"parsedUrl\":{\"origin\":\"https://PLACEHOLDER\",\"pathname\":\"/kibana/app/kibana\",\"basePath\":\"/kibana\"}}},\"params\":{},\"label\":\"modbus.exception.keyword: Descending\",\"aggType\":\"terms\"}]},\"palette\":{\"type\":\"palette\",\"name\":\"kibana_palette\"},\"distinctColors\":true,\"legendDisplay\":\"show\",\"legendSize\":\"auto\"},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"modbus.exception.keyword\",\"orderBy\":\"1\",\"order\":\"desc\",\"size\":25,\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"customLabel\":\"Exception\"}}]}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"93cdb730-75be-11ea-9565-7315f4ee5cac","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"logs-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"}],"sort":[1688135089819,5351],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNTAsMV0="} -{"attributes":{"description":"","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"query\":{\"language\":\"kuery\",\"query\":\"event.dataset:modbus\"},\"filter\":[]}"},"optionsJSON":"{\"hidePanelTitles\":false,\"useMargins\":true}","panelsJSON":"[{\"version\":\"7.9.0\",\"gridData\":{\"x\":0,\"y\":0,\"w\":13,\"h\":8,\"i\":\"dcdc1d0b-bec1-402d-a34b-39464e9a2749\"},\"panelIndex\":\"dcdc1d0b-bec1-402d-a34b-39464e9a2749\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_0\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":13,\"y\":0,\"w\":17,\"h\":8,\"i\":\"ccbb40c9-d2e4-4592-a91f-b1f6912a35f9\"},\"panelIndex\":\"ccbb40c9-d2e4-4592-a91f-b1f6912a35f9\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_1\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":30,\"y\":0,\"w\":18,\"h\":8,\"i\":\"32fd8cfa-64ad-41d7-b4f7-2c71f351916a\"},\"panelIndex\":\"32fd8cfa-64ad-41d7-b4f7-2c71f351916a\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_2\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":0,\"y\":8,\"w\":8,\"h\":19,\"i\":\"b15f438a-6f24-4099-90e6-d66f950029bc\"},\"panelIndex\":\"b15f438a-6f24-4099-90e6-d66f950029bc\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_3\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":8,\"y\":8,\"w\":8,\"h\":19,\"i\":\"089f29d5-cf23-4b6a-8b80-27911ffd6b1a\"},\"panelIndex\":\"089f29d5-cf23-4b6a-8b80-27911ffd6b1a\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_4\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":16,\"y\":8,\"w\":14,\"h\":19,\"i\":\"4154e8b1-e314-4623-aaf4-0404a108551a\"},\"panelIndex\":\"4154e8b1-e314-4623-aaf4-0404a108551a\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_5\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":30,\"y\":8,\"w\":18,\"h\":19,\"i\":\"8acbc44d-4fe2-42b0-a6e9-4a3bc4e4aeb6\"},\"panelIndex\":\"8acbc44d-4fe2-42b0-a6e9-4a3bc4e4aeb6\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_6\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":0,\"y\":27,\"w\":48,\"h\":29,\"i\":\"c4d3c93a-746f-4edc-835c-66f1380fc5d4\"},\"panelIndex\":\"c4d3c93a-746f-4edc-835c-66f1380fc5d4\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_7\"}]","timeRestore":false,"title":"Security Onion - Modbus","version":1},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"886a7b90-75bd-11ea-9565-7315f4ee5cac","migrationVersion":{"dashboard":"8.7.0"},"references":[{"id":"7f822930-6ea4-11ea-9266-1fd14ca6af34","name":"panel_0","type":"visualization"},{"id":"d04b5130-6e99-11ea-9266-1fd14ca6af34","name":"panel_1","type":"visualization"},{"id":"c879ad60-72a1-11ea-8dd2-9d8795a1200b","name":"panel_2","type":"visualization"},{"id":"6b18be30-72a7-11ea-8dd2-9d8795a1200b","name":"panel_3","type":"visualization"},{"id":"b6a4f3f0-72a7-11ea-8dd2-9d8795a1200b","name":"panel_4","type":"visualization"},{"id":"62449800-75be-11ea-9565-7315f4ee5cac","name":"panel_5","type":"visualization"},{"id":"93cdb730-75be-11ea-9565-7315f4ee5cac","name":"panel_6","type":"visualization"},{"id":"8b6f3150-72a2-11ea-8dd2-9d8795a1200b","name":"panel_7","type":"search"}],"sort":[1688135089819,5360],"type":"dashboard","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNTEsMV0="} +{"attributes":{"description":"","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"query\":{\"language\":\"kuery\",\"query\":\"tags:modbus\"},\"filter\":[]}"},"optionsJSON":"{\"hidePanelTitles\":false,\"useMargins\":true}","panelsJSON":"[{\"version\":\"7.9.0\",\"gridData\":{\"x\":0,\"y\":0,\"w\":13,\"h\":8,\"i\":\"dcdc1d0b-bec1-402d-a34b-39464e9a2749\"},\"panelIndex\":\"dcdc1d0b-bec1-402d-a34b-39464e9a2749\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_0\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":13,\"y\":0,\"w\":17,\"h\":8,\"i\":\"ccbb40c9-d2e4-4592-a91f-b1f6912a35f9\"},\"panelIndex\":\"ccbb40c9-d2e4-4592-a91f-b1f6912a35f9\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_1\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":30,\"y\":0,\"w\":18,\"h\":8,\"i\":\"32fd8cfa-64ad-41d7-b4f7-2c71f351916a\"},\"panelIndex\":\"32fd8cfa-64ad-41d7-b4f7-2c71f351916a\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_2\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":0,\"y\":8,\"w\":8,\"h\":19,\"i\":\"b15f438a-6f24-4099-90e6-d66f950029bc\"},\"panelIndex\":\"b15f438a-6f24-4099-90e6-d66f950029bc\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_3\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":8,\"y\":8,\"w\":8,\"h\":19,\"i\":\"089f29d5-cf23-4b6a-8b80-27911ffd6b1a\"},\"panelIndex\":\"089f29d5-cf23-4b6a-8b80-27911ffd6b1a\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_4\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":16,\"y\":8,\"w\":14,\"h\":19,\"i\":\"4154e8b1-e314-4623-aaf4-0404a108551a\"},\"panelIndex\":\"4154e8b1-e314-4623-aaf4-0404a108551a\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_5\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":30,\"y\":8,\"w\":18,\"h\":19,\"i\":\"8acbc44d-4fe2-42b0-a6e9-4a3bc4e4aeb6\"},\"panelIndex\":\"8acbc44d-4fe2-42b0-a6e9-4a3bc4e4aeb6\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_6\"},{\"version\":\"7.9.0\",\"gridData\":{\"x\":0,\"y\":27,\"w\":48,\"h\":29,\"i\":\"c4d3c93a-746f-4edc-835c-66f1380fc5d4\"},\"panelIndex\":\"c4d3c93a-746f-4edc-835c-66f1380fc5d4\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_7\"}]","timeRestore":false,"title":"Security Onion - Modbus","version":1},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"886a7b90-75bd-11ea-9565-7315f4ee5cac","migrationVersion":{"dashboard":"8.7.0"},"references":[{"id":"7f822930-6ea4-11ea-9266-1fd14ca6af34","name":"panel_0","type":"visualization"},{"id":"d04b5130-6e99-11ea-9266-1fd14ca6af34","name":"panel_1","type":"visualization"},{"id":"c879ad60-72a1-11ea-8dd2-9d8795a1200b","name":"panel_2","type":"visualization"},{"id":"6b18be30-72a7-11ea-8dd2-9d8795a1200b","name":"panel_3","type":"visualization"},{"id":"b6a4f3f0-72a7-11ea-8dd2-9d8795a1200b","name":"panel_4","type":"visualization"},{"id":"62449800-75be-11ea-9565-7315f4ee5cac","name":"panel_5","type":"visualization"},{"id":"93cdb730-75be-11ea-9565-7315f4ee5cac","name":"panel_6","type":"visualization"},{"id":"8b6f3150-72a2-11ea-8dd2-9d8795a1200b","name":"panel_7","type":"search"}],"sort":[1688135089819,5360],"type":"dashboard","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNTEsMV0="} {"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[]}"},"savedSearchRefName":"search_0","title":"SSH - Source IP Address","uiStateJSON":"{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}","version":1,"visState":"{\"title\":\"SSH - Source IP Address\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\",\"showToolbar\":true},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"source_ip\",\"size\":100,\"order\":\"desc\",\"orderBy\":\"1\",\"customLabel\":\"IP Address\"}}],\"listeners\":{}}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"8a60eb50-365f-11e7-8c78-e3086faf385c","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"c33e7600-342e-11e7-9e93-53b62e1857b2","name":"search_0","type":"search"}],"sort":[1688135089819,5362],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNTIsMV0="} {"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"title":"Security Onion - SSH - HASSH","uiStateJSON":"{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}","version":1,"visState":"{\"title\":\"Security Onion - SSH - HASSH\",\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMetricsAtAllLevels\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"showTotal\":false,\"totalFunc\":\"sum\",\"percentageCol\":\"\",\"dimensions\":{\"metrics\":[{\"accessor\":0,\"format\":{\"id\":\"number\"},\"params\":{},\"label\":\"Count\",\"aggType\":\"count\"}],\"buckets\":[]},\"showToolbar\":true},\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"hash.hassh.keyword\",\"orderBy\":\"1\",\"order\":\"desc\",\"size\":100,\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\"}}]}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"8afa5f50-75eb-11ea-9565-7315f4ee5cac","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"logs-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"}],"sort":[1688135089819,5364],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNTMsMV0="} {"attributes":{"description":"based on the Endgame - Categories with Full Event Type viz, modded by rlp 20211220","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"query\":{\"language\":\"kuery\",\"query\":\"\"},\"filter\":[],\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\"}"},"title":"Endgame - Event Categories","uiStateJSON":"{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":0,\"direction\":\"asc\"}}}}","version":1,"visState":"{\"title\":\"Endgame - Event Categories\",\"type\":\"table\",\"aggs\":[{\"id\":\"1\",\"enabled\":true,\"type\":\"count\",\"params\":{},\"schema\":\"metric\"},{\"id\":\"2\",\"enabled\":true,\"type\":\"terms\",\"params\":{\"field\":\"event.category\",\"orderBy\":\"1\",\"order\":\"desc\",\"size\":100,\"otherBucket\":false,\"otherBucketLabel\":\"Other\",\"missingBucket\":false,\"missingBucketLabel\":\"Missing\",\"customLabel\":\"event.category\"},\"schema\":\"bucket\"}],\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMetricsAtAllLevels\":false,\"showTotal\":false,\"showToolbar\":false,\"totalFunc\":\"sum\",\"percentageCol\":\"\",\"row\":true}}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"8b3bb5c0-61af-11ec-864c-8b5450f97635","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"endgame-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"},{"id":"41a5e270-53b1-11ec-b3ef-6bcc33056a36","name":"tag-41a5e270-53b1-11ec-b3ef-6bcc33056a36","type":"tag"}],"sort":[1688135089819,5367],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQzNTQsMV0="} @@ -951,4 +951,4 @@ {"attributes":{"description":"Overview dashboard for powershell integration.","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"language\":\"kuery\",\"query\":\"(data_stream.dataset:windows.powershell OR data_stream.dataset:windows.powershell_operational)\"}}"},"optionsJSON":"{\"hidePanelTitles\":false,\"useMargins\":true}","panelsJSON":"[{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":8,\"i\":\"fa41e799-b6b3-49ec-a11c-3f20231a4a79\",\"w\":13,\"x\":0,\"y\":0},\"panelIndex\":\"fa41e799-b6b3-49ec-a11c-3f20231a4a79\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_fa41e799-b6b3-49ec-a11c-3f20231a4a79\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":6,\"i\":\"65ce6b63-6ce0-4094-ab23-189126fc169f\",\"w\":7,\"x\":13,\"y\":0},\"panelIndex\":\"65ce6b63-6ce0-4094-ab23-189126fc169f\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_65ce6b63-6ce0-4094-ab23-189126fc169f\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":6,\"i\":\"314e6f55-a05a-4ae3-ab76-bcae7f2074ab\",\"w\":8,\"x\":20,\"y\":0},\"panelIndex\":\"314e6f55-a05a-4ae3-ab76-bcae7f2074ab\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_314e6f55-a05a-4ae3-ab76-bcae7f2074ab\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":6,\"i\":\"a1f161f6-1abe-4177-9ede-4d1984f5a963\",\"w\":7,\"x\":28,\"y\":0},\"panelIndex\":\"a1f161f6-1abe-4177-9ede-4d1984f5a963\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_a1f161f6-1abe-4177-9ede-4d1984f5a963\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":6,\"i\":\"6b7ed122-22f3-4e9d-89eb-8de92c0d2033\",\"w\":4,\"x\":35,\"y\":0},\"panelIndex\":\"6b7ed122-22f3-4e9d-89eb-8de92c0d2033\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_6b7ed122-22f3-4e9d-89eb-8de92c0d2033\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":6,\"i\":\"d536f6a7-ad28-4a32-9319-9e0b983828bf\",\"w\":4,\"x\":39,\"y\":0},\"panelIndex\":\"d536f6a7-ad28-4a32-9319-9e0b983828bf\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_d536f6a7-ad28-4a32-9319-9e0b983828bf\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":6,\"i\":\"eda6d08f-b45e-448a-bf9f-afa5516d4b4b\",\"w\":4,\"x\":43,\"y\":0},\"panelIndex\":\"eda6d08f-b45e-448a-bf9f-afa5516d4b4b\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_eda6d08f-b45e-448a-bf9f-afa5516d4b4b\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":10,\"i\":\"56d2dd76-6fec-422b-96e9-22791b0c5f0c\",\"w\":10,\"x\":13,\"y\":6},\"panelIndex\":\"56d2dd76-6fec-422b-96e9-22791b0c5f0c\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_56d2dd76-6fec-422b-96e9-22791b0c5f0c\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":7,\"i\":\"3e4a9683-fd6a-4ad7-b05f-c71bcb4d92d5\",\"w\":12,\"x\":23,\"y\":6},\"panelIndex\":\"3e4a9683-fd6a-4ad7-b05f-c71bcb4d92d5\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_3e4a9683-fd6a-4ad7-b05f-c71bcb4d92d5\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":7,\"i\":\"a8c00572-667b-4e39-8b0c-10be56fbadd5\",\"w\":12,\"x\":35,\"y\":6},\"panelIndex\":\"a8c00572-667b-4e39-8b0c-10be56fbadd5\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_a8c00572-667b-4e39-8b0c-10be56fbadd5\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":8,\"i\":\"e8a57cba-14d2-4cd9-a727-f5e30165f6ba\",\"w\":13,\"x\":0,\"y\":8},\"panelIndex\":\"e8a57cba-14d2-4cd9-a727-f5e30165f6ba\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_e8a57cba-14d2-4cd9-a727-f5e30165f6ba\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":7,\"i\":\"8ae39cfa-cb06-45eb-880e-b749c3355d61\",\"w\":12,\"x\":23,\"y\":13},\"panelIndex\":\"8ae39cfa-cb06-45eb-880e-b749c3355d61\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_8ae39cfa-cb06-45eb-880e-b749c3355d61\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":7,\"i\":\"ef92d192-b56d-476c-b640-e226679ed178\",\"w\":12,\"x\":35,\"y\":13},\"panelIndex\":\"ef92d192-b56d-476c-b640-e226679ed178\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_ef92d192-b56d-476c-b640-e226679ed178\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":11,\"i\":\"b15dcac5-3616-4b41-8abb-cb28398b16f4\",\"w\":13,\"x\":0,\"y\":16},\"panelIndex\":\"b15dcac5-3616-4b41-8abb-cb28398b16f4\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_b15dcac5-3616-4b41-8abb-cb28398b16f4\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":11,\"i\":\"23af61c8-6a45-4d7d-9905-8ed265328130\",\"w\":10,\"x\":13,\"y\":16},\"panelIndex\":\"23af61c8-6a45-4d7d-9905-8ed265328130\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_23af61c8-6a45-4d7d-9905-8ed265328130\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":7,\"i\":\"390068ed-b7fb-4ec1-87d5-e89f7cc82e04\",\"w\":12,\"x\":23,\"y\":20},\"panelIndex\":\"390068ed-b7fb-4ec1-87d5-e89f7cc82e04\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_390068ed-b7fb-4ec1-87d5-e89f7cc82e04\"},{\"version\":\"7.6.0\",\"type\":\"visualization\",\"gridData\":{\"h\":7,\"i\":\"45724dca-fea2-4f3b-af79-cf89bb12a31b\",\"w\":12,\"x\":35,\"y\":20},\"panelIndex\":\"45724dca-fea2-4f3b-af79-cf89bb12a31b\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_45724dca-fea2-4f3b-af79-cf89bb12a31b\"},{\"version\":\"7.6.0\",\"type\":\"search\",\"gridData\":{\"h\":14,\"i\":\"7f0c4a51-d972-42a5-ba0a-d3de814c7440\",\"w\":47,\"x\":0,\"y\":27},\"panelIndex\":\"7f0c4a51-d972-42a5-ba0a-d3de814c7440\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_7f0c4a51-d972-42a5-ba0a-d3de814c7440\"}]","timeRestore":false,"title":"[Windows powershell] Overview","version":1},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"windows-c77e06c0-9e7c-11ea-af6f-cfdb1ee1d6c8","migrationVersion":{"dashboard":"8.7.0"},"references":[{"id":"windows-9ec52c30-9e91-11ea-af6f-cfdb1ee1d6c8","name":"fa41e799-b6b3-49ec-a11c-3f20231a4a79:panel_fa41e799-b6b3-49ec-a11c-3f20231a4a79","type":"visualization"},{"id":"windows-52543ef0-9e95-11ea-af6f-cfdb1ee1d6c8","name":"65ce6b63-6ce0-4094-ab23-189126fc169f:panel_65ce6b63-6ce0-4094-ab23-189126fc169f","type":"visualization"},{"id":"windows-7f3e7710-9e94-11ea-af6f-cfdb1ee1d6c8","name":"314e6f55-a05a-4ae3-ab76-bcae7f2074ab:panel_314e6f55-a05a-4ae3-ab76-bcae7f2074ab","type":"visualization"},{"id":"windows-78874900-9f30-11ea-bef1-95118e62a7c1","name":"a1f161f6-1abe-4177-9ede-4d1984f5a963:panel_a1f161f6-1abe-4177-9ede-4d1984f5a963","type":"visualization"},{"id":"windows-e64ff750-9f28-11ea-bef1-95118e62a7c1","name":"6b7ed122-22f3-4e9d-89eb-8de92c0d2033:panel_6b7ed122-22f3-4e9d-89eb-8de92c0d2033","type":"visualization"},{"id":"windows-2dbabdf0-9f29-11ea-bef1-95118e62a7c1","name":"d536f6a7-ad28-4a32-9319-9e0b983828bf:panel_d536f6a7-ad28-4a32-9319-9e0b983828bf","type":"visualization"},{"id":"windows-92a2a6b0-9f29-11ea-bef1-95118e62a7c1","name":"eda6d08f-b45e-448a-bf9f-afa5516d4b4b:panel_eda6d08f-b45e-448a-bf9f-afa5516d4b4b","type":"visualization"},{"id":"windows-e20b3940-9e9a-11ea-af6f-cfdb1ee1d6c8","name":"56d2dd76-6fec-422b-96e9-22791b0c5f0c:panel_56d2dd76-6fec-422b-96e9-22791b0c5f0c","type":"visualization"},{"id":"windows-1eeaaf70-9f23-11ea-bef1-95118e62a7c1","name":"3e4a9683-fd6a-4ad7-b05f-c71bcb4d92d5:panel_3e4a9683-fd6a-4ad7-b05f-c71bcb4d92d5","type":"visualization"},{"id":"windows-f9fa55f0-9f34-11ea-bef1-95118e62a7c1","name":"a8c00572-667b-4e39-8b0c-10be56fbadd5:panel_a8c00572-667b-4e39-8b0c-10be56fbadd5","type":"visualization"},{"id":"windows-3e55daa0-9e8e-11ea-af6f-cfdb1ee1d6c8","name":"e8a57cba-14d2-4cd9-a727-f5e30165f6ba:panel_e8a57cba-14d2-4cd9-a727-f5e30165f6ba","type":"visualization"},{"id":"windows-d27dea70-9f32-11ea-bef1-95118e62a7c1","name":"8ae39cfa-cb06-45eb-880e-b749c3355d61:panel_8ae39cfa-cb06-45eb-880e-b749c3355d61","type":"visualization"},{"id":"windows-fbb025e0-9e7c-11ea-af6f-cfdb1ee1d6c8","name":"ef92d192-b56d-476c-b640-e226679ed178:panel_ef92d192-b56d-476c-b640-e226679ed178","type":"visualization"},{"id":"windows-7adbce50-9e96-11ea-af6f-cfdb1ee1d6c8","name":"b15dcac5-3616-4b41-8abb-cb28398b16f4:panel_b15dcac5-3616-4b41-8abb-cb28398b16f4","type":"visualization"},{"id":"windows-70751050-9f33-11ea-bef1-95118e62a7c1","name":"23af61c8-6a45-4d7d-9905-8ed265328130:panel_23af61c8-6a45-4d7d-9905-8ed265328130","type":"visualization"},{"id":"windows-b0c5d570-9e7c-11ea-af6f-cfdb1ee1d6c8","name":"390068ed-b7fb-4ec1-87d5-e89f7cc82e04:panel_390068ed-b7fb-4ec1-87d5-e89f7cc82e04","type":"visualization"},{"id":"windows-c0945210-9e8b-11ea-af6f-cfdb1ee1d6c8","name":"45724dca-fea2-4f3b-af79-cf89bb12a31b:panel_45724dca-fea2-4f3b-af79-cf89bb12a31b","type":"visualization"},{"id":"windows-11a61760-9f27-11ea-bef1-95118e62a7c1","name":"7f0c4a51-d972-42a5-ba0a-d3de814c7440:panel_7f0c4a51-d972-42a5-ba0a-d3de814c7440","type":"search"},{"id":"fleet-managed-default","name":"tag-ref-fleet-managed-default","type":"tag"},{"id":"fleet-pkg-windows-default","name":"tag-ref-fleet-pkg-windows-default","type":"tag"}],"sort":[1688135089819,8588],"type":"dashboard","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQ4NzIsMV0="} {"attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"indexRefName\":\"kibanaSavedObjectMeta.searchSourceJSON.index\",\"query\":{\"language\":\"kuery\",\"query\":\"\"}}"},"title":"Service States [Metrics Windows]","uiStateJSON":"{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}}}","version":1,"visState":"{\"aggs\":[{\"enabled\":true,\"id\":\"1\",\"params\":{\"aggregate\":\"concat\",\"customLabel\":\"Latest Report\",\"field\":\"@timestamp\",\"size\":1,\"sortField\":\"@timestamp\",\"sortOrder\":\"desc\"},\"schema\":\"metric\",\"type\":\"top_hits\"},{\"enabled\":true,\"id\":\"2\",\"params\":{\"customLabel\":\"Service\",\"field\":\"windows.service.display_name\",\"order\":\"asc\",\"orderBy\":\"_term\",\"size\":100},\"schema\":\"bucket\",\"type\":\"terms\"},{\"enabled\":true,\"id\":\"5\",\"params\":{\"customLabel\":\"Host\",\"field\":\"host.name\",\"order\":\"desc\",\"orderBy\":\"_term\",\"size\":5},\"schema\":\"bucket\",\"type\":\"terms\"},{\"enabled\":true,\"id\":\"3\",\"params\":{\"customLabel\":\"State\",\"field\":\"windows.service.state\",\"order\":\"desc\",\"orderAgg\":{\"enabled\":true,\"id\":\"3-orderAgg\",\"params\":{\"field\":\"@timestamp\"},\"schema\":\"orderAgg\",\"type\":\"max\"},\"orderBy\":\"custom\",\"size\":1},\"schema\":\"bucket\",\"type\":\"terms\"},{\"enabled\":true,\"id\":\"4\",\"params\":{\"customLabel\":\"Startup Type\",\"field\":\"windows.service.start_type\",\"order\":\"desc\",\"orderAgg\":{\"enabled\":true,\"id\":\"4-orderAgg\",\"params\":{\"field\":\"@timestamp\"},\"schema\":\"orderAgg\",\"type\":\"max\"},\"orderBy\":\"custom\",\"size\":1},\"schema\":\"bucket\",\"type\":\"terms\"}],\"params\":{\"perPage\":10,\"showMeticsAtAllLevels\":false,\"showPartialRows\":false,\"showTotal\":false,\"sort\":{\"columnIndex\":null,\"direction\":null},\"totalFunc\":\"sum\",\"showToolbar\":true},\"title\":\"Service States [Metrics Windows]\",\"type\":\"table\"}"},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"windows-eb8277d0-c98c-11e7-9835-2f31fe08873b","migrationVersion":{"visualization":"8.5.0"},"references":[{"id":"metrics-*","name":"kibanaSavedObjectMeta.searchSourceJSON.index","type":"index-pattern"},{"id":"fleet-managed-default","name":"tag-ref-fleet-managed-default","type":"tag"},{"id":"fleet-pkg-windows-default","name":"tag-ref-fleet-pkg-windows-default","type":"tag"}],"sort":[1688135089819,8592],"type":"visualization","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQ4NzMsMV0="} {"attributes":{"description":"Overview of the Windows Service States","hits":0,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"highlightAll\":true,\"query\":{\"language\":\"kuery\",\"query\":\"data_stream.dataset:windows.service\"},\"version\":true}"},"optionsJSON":"{\"darkTheme\":false}","panelsJSON":"[{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"h\":20,\"i\":\"1\",\"w\":36,\"x\":12,\"y\":12},\"panelIndex\":\"1\",\"embeddableConfig\":{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}},\"enhancements\":{}},\"panelRefName\":\"panel_1\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"h\":20,\"i\":\"2\",\"w\":12,\"x\":0,\"y\":12},\"panelIndex\":\"2\",\"embeddableConfig\":{\"vis\":{\"params\":{\"sort\":{\"columnIndex\":null,\"direction\":null}}},\"enhancements\":{}},\"panelRefName\":\"panel_2\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"h\":12,\"i\":\"3\",\"w\":16,\"x\":0,\"y\":0},\"panelIndex\":\"3\",\"embeddableConfig\":{\"enhancements\":{}},\"panelRefName\":\"panel_3\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"h\":12,\"i\":\"4\",\"w\":16,\"x\":16,\"y\":0},\"panelIndex\":\"4\",\"embeddableConfig\":{\"vis\":{\"defaultColors\":{\"0 - 100\":\"rgb(0,104,55)\"}},\"enhancements\":{}},\"panelRefName\":\"panel_4\"},{\"version\":\"7.3.0\",\"type\":\"visualization\",\"gridData\":{\"h\":12,\"i\":\"5\",\"w\":16,\"x\":32,\"y\":0},\"panelIndex\":\"5\",\"embeddableConfig\":{\"vis\":{\"defaultColors\":{\"0 - 100\":\"rgb(0,104,55)\"}},\"enhancements\":{}},\"panelRefName\":\"panel_5\"}]","timeRestore":false,"title":"[Metrics Windows] Services","version":1},"coreMigrationVersion":"8.7.1","created_at":"2023-06-30T14:24:49.819Z","id":"windows-d9eba730-c991-11e7-9835-2f31fe08873b","migrationVersion":{"dashboard":"8.7.0"},"references":[{"id":"windows-eb8277d0-c98c-11e7-9835-2f31fe08873b","name":"1:panel_1","type":"visualization"},{"id":"windows-23a5fff0-c98e-11e7-9835-2f31fe08873b","name":"2:panel_2","type":"visualization"},{"id":"windows-830c45f0-c991-11e7-9835-2f31fe08873b","name":"3:panel_3","type":"visualization"},{"id":"windows-35f5ad60-c996-11e7-9835-2f31fe08873b","name":"4:panel_4","type":"visualization"},{"id":"windows-c36b2ba0-ca29-11e7-9835-2f31fe08873b","name":"5:panel_5","type":"visualization"},{"id":"fleet-managed-default","name":"tag-ref-fleet-managed-default","type":"tag"},{"id":"fleet-pkg-windows-default","name":"tag-ref-fleet-pkg-windows-default","type":"tag"}],"sort":[1688135089819,8600],"type":"dashboard","updated_at":"2023-06-30T14:24:49.819Z","version":"WzQ4NzQsMV0="} -{"excludedObjects":[],"excludedObjectsCount":0,"exportedCount":953,"missingRefCount":0,"missingReferences":[]} \ No newline at end of file +{"excludedObjects":[],"excludedObjectsCount":0,"exportedCount":953,"missingRefCount":0,"missingReferences":[]}