|
33 | 33 | { |
34 | 34 | "id": 1782623543348740, |
35 | 35 | "definition": { |
36 | | - "title": "Attacks Blocked", |
| 36 | + "title": "Distribution of Attack Events", |
37 | 37 | "title_size": "16", |
38 | 38 | "title_align": "left", |
39 | 39 | "requests": [ |
40 | 40 | { |
41 | | - "response_format": "scalar", |
42 | 41 | "queries": [ |
43 | 42 | { |
44 | 43 | "name": "query1", |
45 | 44 | "data_source": "logs", |
46 | 45 | "search": { |
47 | | - "query": "source:contrastadr" |
| 46 | + "query": "source:contrast-security-adr tags:attack_event" |
48 | 47 | }, |
49 | 48 | "indexes": [ |
50 | 49 | "*" |
|
59 | 58 | "metric": "count" |
60 | 59 | }, |
61 | 60 | "should_exclude_missing": true |
62 | | - }, |
63 | | - { |
64 | | - "facet": "@application.name", |
65 | | - "limit": 10, |
66 | | - "sort": { |
67 | | - "aggregation": "count", |
68 | | - "order": "desc", |
69 | | - "metric": "count" |
70 | | - }, |
71 | | - "should_exclude_missing": true |
72 | 61 | } |
73 | 62 | ], |
74 | 63 | "compute": { |
|
77 | 66 | "storage": "hot" |
78 | 67 | } |
79 | 68 | ], |
| 69 | + "response_format": "scalar", |
80 | 70 | "style": { |
81 | 71 | "palette": "datadog16" |
82 | 72 | }, |
|
86 | 76 | } |
87 | 77 | ], |
88 | 78 | "sort": { |
89 | | - "count": 100, |
| 79 | + "count": 10, |
90 | 80 | "order_by": [ |
91 | 81 | { |
92 | 82 | "type": "formula", |
|
112 | 102 | { |
113 | 103 | "id": 2595467198821652, |
114 | 104 | "definition": { |
115 | | - "title": "Attacks by Applications", |
| 105 | + "title": "Top 10 Attacks by Applications", |
116 | 106 | "title_size": "16", |
117 | 107 | "title_align": "left", |
| 108 | + "type": "toplist", |
118 | 109 | "requests": [ |
119 | 110 | { |
120 | | - "response_format": "scalar", |
121 | 111 | "queries": [ |
122 | 112 | { |
123 | 113 | "name": "query1", |
124 | 114 | "data_source": "logs", |
125 | 115 | "search": { |
126 | | - "query": "source:contrastadr @application.name:*" |
| 116 | + "query": "source:contrast-security-adr tags:attack_event" |
127 | 117 | }, |
128 | 118 | "indexes": [ |
129 | 119 | "*" |
|
146 | 136 | "storage": "hot" |
147 | 137 | } |
148 | 138 | ], |
149 | | - "style": { |
150 | | - "palette": "datadog16" |
151 | | - }, |
| 139 | + "response_format": "scalar", |
152 | 140 | "formulas": [ |
153 | 141 | { |
154 | 142 | "formula": "query1" |
|
166 | 154 | } |
167 | 155 | } |
168 | 156 | ], |
169 | | - "type": "sunburst", |
170 | | - "legend": { |
171 | | - "type": "automatic" |
| 157 | + "style": { |
| 158 | + "display": { |
| 159 | + "type": "stacked", |
| 160 | + "legend": "automatic" |
| 161 | + } |
172 | 162 | } |
173 | 163 | }, |
174 | 164 | "layout": { |
|
181 | 171 | { |
182 | 172 | "id": 1701489096793870, |
183 | 173 | "definition": { |
184 | | - "title": "Attacks by Type", |
| 174 | + "title": "Top 10 Attacks by Rule", |
185 | 175 | "title_size": "16", |
186 | 176 | "title_align": "left", |
187 | 177 | "type": "toplist", |
|
192 | 182 | "name": "query1", |
193 | 183 | "data_source": "logs", |
194 | 184 | "search": { |
195 | | - "query": "source:contrastadr @rule:*" |
| 185 | + "query": "source:contrast-security-adr tags:attack_event" |
196 | 186 | }, |
197 | 187 | "indexes": [ |
198 | 188 | "*" |
|
207 | 197 | "metric": "count" |
208 | 198 | }, |
209 | 199 | "should_exclude_missing": true |
210 | | - }, |
211 | | - { |
212 | | - "facet": "@application.name", |
213 | | - "limit": 10, |
214 | | - "sort": { |
215 | | - "aggregation": "count", |
216 | | - "order": "desc", |
217 | | - "metric": "count" |
218 | | - }, |
219 | | - "should_exclude_missing": true |
220 | 200 | } |
221 | 201 | ], |
222 | 202 | "compute": { |
|
232 | 212 | } |
233 | 213 | ], |
234 | 214 | "sort": { |
235 | | - "count": 100, |
| 215 | + "count": 10, |
236 | 216 | "order_by": [ |
237 | 217 | { |
238 | 218 | "type": "formula", |
|
247 | 227 | "display": { |
248 | 228 | "type": "stacked", |
249 | 229 | "legend": "automatic" |
250 | | - }, |
251 | | - "palette": "datadog16" |
| 230 | + } |
252 | 231 | } |
253 | 232 | }, |
254 | 233 | "layout": { |
255 | 234 | "x": 0, |
256 | 235 | "y": 4, |
257 | | - "width": 6, |
| 236 | + "width": 5, |
258 | 237 | "height": 4 |
259 | 238 | } |
260 | 239 | }, |
261 | 240 | { |
262 | 241 | "id": 2205300797772388, |
263 | 242 | "definition": { |
264 | | - "title": "Top 10 Most Attacked URIs", |
| 243 | + "title": "Top 10 Most Attacked URLs", |
265 | 244 | "title_size": "16", |
266 | 245 | "title_align": "left", |
267 | | - "type": "toplist", |
| 246 | + "type": "query_table", |
268 | 247 | "requests": [ |
269 | 248 | { |
270 | | - "response_format": "scalar", |
271 | 249 | "queries": [ |
272 | 250 | { |
273 | 251 | "name": "query1", |
274 | 252 | "data_source": "logs", |
275 | 253 | "search": { |
276 | | - "query": "source:contrastadr" |
| 254 | + "query": "source:contrast-security-adr tags:attack_event" |
277 | 255 | }, |
278 | 256 | "indexes": [ |
279 | 257 | "*" |
280 | 258 | ], |
281 | 259 | "group_by": [ |
282 | 260 | { |
283 | | - "facet": "@attackPayload.url", |
| 261 | + "facet": "@url", |
284 | 262 | "limit": 10, |
285 | 263 | "sort": { |
286 | 264 | "aggregation": "count", |
|
306 | 284 | "storage": "hot" |
307 | 285 | } |
308 | 286 | ], |
309 | | - "formulas": [ |
310 | | - { |
311 | | - "formula": "query1" |
312 | | - } |
313 | | - ], |
| 287 | + "response_format": "scalar", |
314 | 288 | "sort": { |
315 | 289 | "count": 100, |
316 | 290 | "order_by": [ |
|
320 | 294 | "order": "desc" |
321 | 295 | } |
322 | 296 | ] |
323 | | - } |
| 297 | + }, |
| 298 | + "formulas": [ |
| 299 | + { |
| 300 | + "cell_display_mode": "bar", |
| 301 | + "formula": "query1" |
| 302 | + } |
| 303 | + ] |
324 | 304 | } |
325 | 305 | ], |
326 | | - "style": { |
327 | | - "display": { |
328 | | - "type": "stacked", |
329 | | - "legend": "automatic" |
330 | | - } |
331 | | - } |
| 306 | + "has_search_bar": "auto" |
332 | 307 | }, |
333 | 308 | "layout": { |
334 | | - "x": 6, |
| 309 | + "x": 5, |
335 | 310 | "y": 4, |
336 | | - "width": 6, |
| 311 | + "width": 7, |
337 | 312 | "height": 4 |
338 | 313 | } |
339 | 314 | }, |
340 | 315 | { |
341 | 316 | "id": 4349148145843182, |
342 | 317 | "definition": { |
343 | | - "title": "Attacks by Type and Time", |
| 318 | + "title": "Attack Timeline", |
344 | 319 | "title_size": "16", |
345 | 320 | "title_align": "left", |
346 | 321 | "show_legend": true, |
|
361 | 336 | "name": "query1", |
362 | 337 | "data_source": "logs", |
363 | 338 | "search": { |
364 | | - "query": "source:contrastadr" |
| 339 | + "query": "source:contrast-security-adr tags:attack_event" |
365 | 340 | }, |
366 | 341 | "indexes": [ |
367 | 342 | "*" |
368 | 343 | ], |
369 | | - "group_by": [ |
370 | | - { |
371 | | - "facet": "@rule", |
372 | | - "limit": 10, |
373 | | - "sort": { |
374 | | - "aggregation": "count", |
375 | | - "order": "desc", |
376 | | - "metric": "count" |
377 | | - }, |
378 | | - "should_exclude_missing": true |
379 | | - }, |
380 | | - { |
381 | | - "facet": "@application.name", |
382 | | - "limit": 10, |
383 | | - "sort": { |
384 | | - "aggregation": "count", |
385 | | - "order": "desc", |
386 | | - "metric": "count" |
387 | | - }, |
388 | | - "should_exclude_missing": true |
389 | | - } |
390 | | - ], |
| 344 | + "group_by": [], |
391 | 345 | "compute": { |
392 | 346 | "aggregation": "count" |
393 | 347 | }, |
|
406 | 360 | "line_width": "normal" |
407 | 361 | }, |
408 | 362 | "display_type": "line" |
| 363 | + }, |
| 364 | + { |
| 365 | + "response_format": "timeseries", |
| 366 | + "queries": [ |
| 367 | + { |
| 368 | + "data_source": "events", |
| 369 | + "name": "dashboard_events_overlay", |
| 370 | + "indexes": [ |
| 371 | + "*" |
| 372 | + ], |
| 373 | + "compute": { |
| 374 | + "aggregation": "count" |
| 375 | + }, |
| 376 | + "group_by": [], |
| 377 | + "search": { |
| 378 | + "query": "" |
| 379 | + } |
| 380 | + } |
| 381 | + ], |
| 382 | + "formulas": [ |
| 383 | + { |
| 384 | + "formula": "dashboard_events_overlay" |
| 385 | + } |
| 386 | + ], |
| 387 | + "display_type": "overlay" |
409 | 388 | } |
410 | 389 | ] |
411 | 390 | }, |
|
0 commit comments