mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-04-28 07:28:00 +02:00
595 lines
11 KiB
Django/Jinja
595 lines
11 KiB
Django/Jinja
{
|
|
"type": "graph",
|
|
"title": "Panel Title",
|
|
"gridPos": {
|
|
"x": 0,
|
|
"y": 0,
|
|
"w": 24,
|
|
"h": 14
|
|
},
|
|
"id": 78,
|
|
"targets": [
|
|
{
|
|
"refId": "A",
|
|
"queryType": "randomWalk",
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-elasticsearch"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
" /$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"query": "SELECT mean(\"usage_percent\") /$cpucount FROM \"docker_container_cpu\" WHERE (\"host\" = '$servername' AND \"container_name\" = 'so-elasticsearch') AND $timeFilter GROUP BY time($__interval) fill(null)",
|
|
"rawQuery": false,
|
|
"hide": false,
|
|
"alias": "elasticsearch"
|
|
},
|
|
{
|
|
"refId": "B",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-filebeat"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
" /$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "filebeat"
|
|
},
|
|
{
|
|
"refId": "C",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-influxdb"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
" /$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "influxdb"
|
|
},
|
|
{
|
|
"refId": "D",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-logstash"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
" /$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "logstash"
|
|
},
|
|
{
|
|
"refId": "E",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-zeek"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
"/$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"alias": "zeek",
|
|
"measurement": "docker_container_cpu"
|
|
},
|
|
{
|
|
"refId": "F",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-suricata"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"value"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
"/$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "suricata"
|
|
},
|
|
{
|
|
"refId": "G",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-steno"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
"/$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "steno"
|
|
},
|
|
{
|
|
"refId": "H",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-kibana"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
"/$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "kibana"
|
|
},
|
|
{
|
|
"refId": "I",
|
|
"hide": false,
|
|
"policy": "default",
|
|
"resultFormat": "time_series",
|
|
"orderByTime": "ASC",
|
|
"tags": [
|
|
{
|
|
"key": "host",
|
|
"operator": "=",
|
|
"value": "$servername"
|
|
},
|
|
{
|
|
"condition": "AND",
|
|
"key": "container_name",
|
|
"operator": "=",
|
|
"value": "so-redis"
|
|
}
|
|
],
|
|
"groupBy": [
|
|
{
|
|
"type": "time",
|
|
"params": [
|
|
"$__interval"
|
|
]
|
|
},
|
|
{
|
|
"type": "fill",
|
|
"params": [
|
|
"null"
|
|
]
|
|
}
|
|
],
|
|
"select": [
|
|
[
|
|
{
|
|
"type": "field",
|
|
"params": [
|
|
"usage_percent"
|
|
]
|
|
},
|
|
{
|
|
"type": "mean",
|
|
"params": []
|
|
},
|
|
{
|
|
"type": "math",
|
|
"params": [
|
|
"/$cpucount"
|
|
]
|
|
}
|
|
]
|
|
],
|
|
"measurement": "docker_container_cpu",
|
|
"alias": "redis"
|
|
}
|
|
],
|
|
"options": {
|
|
"alertThreshold": true
|
|
},
|
|
"datasource": "InfluxDB",
|
|
"fieldConfig": {
|
|
"defaults": {},
|
|
"overrides": []
|
|
},
|
|
"pluginVersion": "7.5.4",
|
|
"renderer": "flot",
|
|
"yaxes": [
|
|
{
|
|
"label": null,
|
|
"show": true,
|
|
"logBase": 1,
|
|
"min": null,
|
|
"max": null,
|
|
"format": "short"
|
|
},
|
|
{
|
|
"label": null,
|
|
"show": true,
|
|
"logBase": 1,
|
|
"min": null,
|
|
"max": null,
|
|
"format": "short"
|
|
}
|
|
],
|
|
"xaxis": {
|
|
"show": true,
|
|
"mode": "time",
|
|
"name": null,
|
|
"values": [],
|
|
"buckets": null
|
|
},
|
|
"yaxis": {
|
|
"align": false,
|
|
"alignLevel": null
|
|
},
|
|
"lines": true,
|
|
"fill": 1,
|
|
"linewidth": 1,
|
|
"dashLength": 10,
|
|
"spaceLength": 10,
|
|
"pointradius": 2,
|
|
"legend": {
|
|
"show": true,
|
|
"values": false,
|
|
"min": false,
|
|
"max": false,
|
|
"current": false,
|
|
"total": false,
|
|
"avg": false
|
|
},
|
|
"nullPointMode": "connected",
|
|
"tooltip": {
|
|
"value_type": "individual",
|
|
"shared": true,
|
|
"sort": 0
|
|
},
|
|
"aliasColors": {},
|
|
"seriesOverrides": [],
|
|
"thresholds": [],
|
|
"timeRegions": [],
|
|
"fillGradient": 0,
|
|
"dashes": false,
|
|
"hiddenSeries": false,
|
|
"points": false,
|
|
"bars": false,
|
|
"stack": false,
|
|
"percentage": false,
|
|
"steppedLine": false,
|
|
"timeFrom": null,
|
|
"timeShift": null
|
|
}
|