%{DAY:day} %{MONTH:month} %{MONTHDAY} %{TIME} %{YEAR})\] \[.*:%{LOGLEVEL:loglevel}\] \[pid %{NUMBER:pid}\] %{GREEDYDATA:errormsg} \[client %{IP:src_ip}:%{DATA:src_port}\] %{GREEDYDATA:errormsg}" }
237 | }
238 | grok {
239 | match => { "message" => "\[%{DATA:timestamp}\] \[%{LOGLEVEL:loglevel}\] (?:\[client %{IP:src_ip}\]) user %{USER:basic_auth_user} not found" }
240 | add_tag => [ "basic_auth_user_not_found"]
241 | remove_tag => [ "_jsonparsefailure", "_grokparsefailure", "_jsonparsefailure_grokparsefailure" ]
242 | }
243 | grok {
244 | match => { "message" => "\[%{DATA:timestamp}\] \[%{LOGLEVEL:loglevel}\] (?:\[client %{IP:src_ip}\]) user %{USER:basic_auth_user}: authentication failure %{GREEDYDATA:apache_errmsg}" }
245 | add_tag => [ "basic_auth_password_mismatch"]
246 | remove_tag => [ "_jsonparsefailure", "_grokparsefailure", "_jsonparsefailure_grokparsefailure" ]
247 | }
248 | geoip {
249 | source => "src_ip"
250 | target => "geoip"
251 | add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
252 | add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
253 | }
254 | mutate {
255 | convert => [ "[geoip][coordinates]", "float" ]
256 | }
257 | }
258 |
259 | if [fields][log_type] == "apache-ssl-access" {
260 | grok {
261 | match => { "message" => "%{IP:src_ip} - %{USER:basic_auth_user} (?:\[%{HTTPDATE}\])? %{QUOTEDSTRING:basic_auth_message} %{NUMBER:basic_auth_response} (?:%{NUMBER:basic_auth_bytes}|-)" }
262 | add_tag => [ "basic_auth_attempt"]
263 | }
264 | if [basic_auth_response] == "401" and "-" not in [basic_auth_user] {
265 | grok {
266 | match => { "message" => "%{IP:src_ip} - %{USER:basic_auth_user} (?:\[%{HTTPDATE}\])? %{QUOTEDSTRING:basic_auth_message} %{NUMBER:basic_auth_response} (?:%{NUMBER:basic_auth_bytes}|-)" }
267 | add_tag => [ "basic_auth_failure"]
268 | remove_tag => [ "_jsonparsefailure", "_grokparsefailure", "_jsonparsefailure_grokparsefailure" ]
269 | }
270 | }
271 | if [basic_auth_response] == "404" and "-" not in [basic_auth_user] {
272 | grok {
273 | match => { "message" => "%{IP:src_ip} - %{USER:basic_auth_user} (?:\[%{HTTPDATE}\])? %{QUOTEDSTRING:basic_auth_message} %{NUMBER:basic_auth_response} (?:%{NUMBER:basic_auth_bytes}|-)" }
274 | add_tag => [ "basic_auth_failure"]
275 | remove_tag => [ "_jsonparsefailure", "_grokparsefailure", "_jsonparsefailure_grokparsefailure" ]
276 | }
277 | }
278 | if [basic_auth_response] == "200" and "-" not in [basic_auth_user] {
279 | mutate {
280 | add_tag => [ "basic_auth_success" ]
281 | remove_tag => [ "_jsonparsefailure", "_grokparsefailure", "_jsonparsefailure_grokparsefailure" ]
282 | }
283 | }
284 |
285 | geoip {
286 | source => "src_ip"
287 | target => "geoip"
288 | add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
289 | add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
290 | }
291 | mutate {
292 | convert => [ "[geoip][coordinates]", "float" ]
293 | }
294 | }
295 |
296 | if [fields][log_type] == "shibboleth" {
297 | grok {
298 | match => [ "message", "%{SYSLOGTIMESTAMP:shib_event_timestamp} %{WORD:shib_notification_type} %{DATA:shib_trans_type}:\ New session \(ID: %{DATA:shib_session_id}\) with \(applicationId: %{DATA:shib_application_id}\) for principal from \(IdP: %{DATA:shib_IdP}\) at \(ClientAddress: %{IP:src_ip}\) with \(NameIdentifier: %{DATA:shib_name_identifier}\) using \(Protocol: %{DATA:shib_protocol}\) from \(AssertionID: %{DATA:shib_assertion_id}\)" ]
299 | }
300 | date {
301 | match => [ "time", "YYYY-MM-dd HH:mm:ss"]
302 | }
303 | geoip {
304 | source => "src_ip"
305 | target => "geoip"
306 | add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
307 | add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
308 | }
309 | mutate {
310 | convert => [ "[geoip][coordinates]", "float" ]
311 | }
312 | }
313 |
314 | if [fields][log_type] == "shibboleth-warn" {
315 | grok {
316 | match => [ "message", "%{SYSLOGTIMESTAMP:shib_warn_event_timestamp} %{WORD:shib_warn_notification_type} %{GREEDYDATA:shib_warn_message}" ]
317 | }
318 | date {
319 | match => [ "time", "YYYY-MM-dd HH:mm:ss"]
320 | }
321 | }
322 |
323 | if [fields][log_type] == "shib_logshipper" {
324 | grok {
325 | match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{GREEDYDATA:logshipper_source} %{WORD:logshipper_type1}: %{GREEDYDATA:logshipper_type2} %{INT:logshipper_timestamp} %{WORD:logshipper_shib_username} %{IP:src_ip}" }
326 | add_tag => [ "shib_logshipper"]
327 | remove_tag => [ "_jsonparsefailure", "_grokparsefailure", "_jsonparsefailure_grokparsefailure" ]
328 | }
329 | geoip {
330 | source => "src_ip"
331 | target => "geoip"
332 | add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
333 | add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
334 | }
335 | mutate {
336 | convert => [ "[geoip][coordinates]", "float" ]
337 | }
338 | }
339 |
340 | if [fields][log_type] == "deny-hosts" {
341 | grok {
342 | match => [ "message", "%{DATA:discard}\ %{SYSLOGTIMESTAMP:timestamp} %{YEAR} %{DATA:discard} %{IP:src_ip}" ]
343 | add_tag => "deny_hosts"
344 | remove_field => [ "%{discard}" ]
345 | }
346 | grok {
347 | match => [ "message", "%{TIMESTAMP_ISO8601:syslog_timestamp} - %{GREEDYDATA:denyhosts_status} \[%{DATA:denyhosts_denied_host}\]" ]
348 | add_tag => "deny_hosts"
349 | }
350 | date {
351 | match => [ "time", "MM dd HH:mm:ss YYYY"]
352 | }
353 | geoip {
354 | source => "src_ip"
355 | target => "geoip"
356 | add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
357 | add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
358 | }
359 | mutate {
360 | convert => [ "[geoip][coordinates]", "float" ]
361 | }
362 | }
363 |
364 | if [fields][log_type] == "yum" {
365 | grok {
366 | match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{DATA:yum_event}\: %{GREEDYDATA:yum_package}" }
367 | add_tag => [ "yum_events" ]
368 | }
369 | }
370 |
371 | if [fields][log_type] == "audit" {
372 | grok {
373 | match => { "message" => "type=%{WORD:audit_type} msg=audit\(%{NUMBER:audit_epoch}:%{NUMBER:audit_counter}\): user pid=%{NUMBER:audit_pid} uid=%{NUMBER:audit_uid} auid=%{NUMBER:audit_audid} ses=%{NUMBER:audit_ses} msg='op=%{DATA:audit_op} acct=%{QUOTEDSTRING:pam_username} exe=%{QUOTEDSTRING:audit_exe} hostname=%{DATA:src_ip} addr=%{DATA:src_ip} terminal=%{DATA:audit_terminal} res=%{DATA:audit_result}'" }
374 | add_tag => [ "audit_log" ]
375 | }
376 | geoip {
377 | source => "src_ip"
378 | target => "geoip"
379 | add_field => ["[geoip][coordinates]","%{[geoip][longitude]}"]
380 | add_field => ["[geoip][coordinates]","%{[geoip][latitude]}"]
381 | }
382 | mutate {
383 | convert => [ "[geoip][coordinates]", "float" ]
384 | }
385 | }
386 |
387 | if [fields][log_type] == "audit-commands" {
388 | grok {
389 | match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{WORD:host_single} %{USER:pam_username}: %{USER:pam_username} (?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:audit_command} (?:\[%{POSINT:audit_command_response}\])?" }
390 | add_tag => [ "audit_log_commands" ]
391 | }
392 | }
393 |
394 | #####################################################
395 | #fping
396 | #####################################################
397 |
398 | if "fping" in [tags] {
399 | grok {
400 | match => { "message" => "%{IP:ping_target_ip} : %{DATA:ping_int}, %{INT:ping_bytes} bytes, %{DATA:ping_ms} ms \(%{DATA:ping_avg} avg, %{INT:ping_loss}% loss\)" }
401 | }
402 | } #if
403 |
404 | if "fping" in [tags] and [ping_loss] == "0" {
405 | mutate { add_tag => "ping_loss_no" }
406 | }
407 | if "fping" in [tags] and [ping_loss] != "0" {
408 | mutate { add_tag => "ping_loss_yes" }
409 | }
410 |
411 | ########################################
412 | #if you wanted to throttle events so
413 | #you only receive an event after 2
414 | #occurrences and you get no more than
415 | #3 in 10 minutes
416 | ########################################
417 |
418 | if "ping_loss_yes" in [tags] {
419 | throttle{
420 | period => 600
421 | before_count => 4
422 | after_count => 5
423 | key => "%{message}"
424 | add_tag => "AlertOnTag_ping_loss_yes"
425 | }
426 |
427 | }
428 |
429 | #####################################################
430 | #port 9000: OSSEC
431 | #####################################################
432 |
433 | if [type] == "syslog" {
434 | grok {
435 | match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_host} %{DATA:syslog_program}: Alert Level: %{NONNEGINT:Alert_Level}; Rule: %{NONNEGINT:Rule} - %{DATA:Description}; Location: %{DATA:Location}; (user: %{USER:User};%{SPACE})?(srcip: %{IP:Src_IP};%{SPACE})?(user: %{USER:User};%{SPACE})?(dstip: %{IP:Dst_IP};%{SPACE})?(src_port: %{NONNEGINT:Src_Port};%{SPACE})?(dst_port: %{NONNEGINT:Dst_Port};%{SPACE})?%{GREEDYDATA:Details}" }
436 | add_tag => [ "ossec"]
437 | add_field => [ "ossec_server", "%{host}" ]
438 | }
439 | mutate {
440 | remove_field => [ "message","syslog_timestamp", "syslog_program", "syslog_host", "syslog_message", "syslog_pid", "@version", "type", "host" ]
441 | }
442 | }
443 |
444 | #####################################################
445 | #port 3515: NXLog
446 | #####################################################
447 | if "tcp_json_windows" in [tags] {
448 | date {
449 | locale => "en"
450 | timezone => "Etc/GMT"
451 | match => [ "EventTime", "YYYY-MM-dd HH:mm:ss" ]
452 | }
453 | }
454 |
455 | #####################################################
456 | #For all: remove certain items from [tags]
457 | #####################################################
458 | if "_grokparsefailure" in [tags] {
459 | mutate {
460 | remove_tag => "_grokparsefailure"
461 | }
462 | }
463 | if "_jsonparsefailure" in [tags] {
464 | mutate {
465 | remove_tag => "_jsonparsefailure"
466 | }
467 | }
468 | if "_jsonparsefailure_grokparsefailure" in [tags] {
469 | mutate {
470 | remove_tag => "_jsonparsefailure_grokparsefailure"
471 | }
472 | }
473 |
474 | #####################################################
475 | #Netflow: convert cisco message to standard message
476 | #####################################################
477 |
478 | if "_grokparsefailure" not in [tags] {
479 | mutate {
480 | rename => ["cisco_message", "message"]
481 | remove_field => ["timestamp"]
482 | }
483 | }
484 |
485 | ##################################################################
486 | #If no Beat (e.g. - OSSEC input), define index as logstash
487 | ##################################################################
488 | if ! [@metadata][beat] {
489 | mutate {
490 | replace => [ '[@metadata][beat]', 'logstash' ]
491 | }
492 | }
493 |
494 | ##################################################################
495 | #Metrics
496 | #https://www.elastic.co/blog/logstash-configuration-tuning
497 | ##################################################################
498 | metrics {
499 | meter => "documents"
500 | add_tag => "metric"
501 | flush_interval => 60
502 | }
503 |
504 | }#END filter
505 |
506 | output {
507 |
508 | ##################################################################
509 | #Output to Elasticearch
510 | ##################################################################
511 | elasticsearch {
512 | hosts => "localhost:9200"
513 | manage_template => false
514 | index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
515 | document_type => "%{[@metadata][type]}"
516 | }
517 |
518 | ##################################################################
519 | #Set standard out codec
520 | ##################################################################
521 | stdout { codec => rubydebug }
522 |
523 | ##################################################################
524 | #Logstash metrics
525 | ##################################################################
526 |
527 |
528 | if "metric" in [tags] {
529 | stdout {
530 | codec => line {
531 | format => "1m rate: %{documents.rate_1m} ( %{documents.count} )"
532 | }
533 | }
534 | }
535 |
536 | if "AlertOnTag_ping_loss_yes" in [tags] {
537 | email {
538 | from => "logstash.alert@nowhere.com"
539 | subject => "UCLA-ISO-ELK Alert: Host Down"
540 | to => "your_email_here"
541 | via => "smtp"
542 | body => "Host: UCLA-ISO-ELK Alert: Host down: %{ping_target}. Original event log entry: %{message}"
543 | htmlbody => "UCLA-ISO-ELK Alert: Host down: %{ping_target}
Original event log entry:
%{message}
"
544 | }
545 | }
546 |
547 |
548 | } #END output
--------------------------------------------------------------------------------
/kibana-searches.json:
--------------------------------------------------------------------------------
1 | [
2 | {
3 | "_id": "Cache-transactions",
4 | "_type": "search",
5 | "_source": {
6 | "sort": [
7 | "@timestamp",
8 | "desc"
9 | ],
10 | "hits": 0,
11 | "description": "",
12 | "title": "Cache transactions",
13 | "version": 1,
14 | "kibanaSavedObjectMeta": {
15 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[],\"query\":{\"query_string\":{\"query\":\"type: redis\",\"analyze_wildcard\":true}}}"
16 | },
17 | "columns": [
18 | "type",
19 | "method",
20 | "path",
21 | "responsetime",
22 | "status"
23 | ]
24 | }
25 | },
26 | {
27 | "_id": "DB-transactions",
28 | "_type": "search",
29 | "_source": {
30 | "sort": [
31 | "@timestamp",
32 | "desc"
33 | ],
34 | "hits": 0,
35 | "description": "",
36 | "title": "DB transactions",
37 | "version": 1,
38 | "kibanaSavedObjectMeta": {
39 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[],\"query\":{\"query_string\":{\"query\":\"type: mysql or type: pgsql or type: mongodb\",\"analyze_wildcard\":true}}}"
40 | },
41 | "columns": [
42 | "type",
43 | "method",
44 | "path",
45 | "responsetime",
46 | "status"
47 | ]
48 | }
49 | },
50 | {
51 | "_id": "Default-Search",
52 | "_type": "search",
53 | "_source": {
54 | "sort": [
55 | "@timestamp",
56 | "desc"
57 | ],
58 | "hits": 0,
59 | "description": "",
60 | "title": "Default Search",
61 | "version": 1,
62 | "kibanaSavedObjectMeta": {
63 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"mongodb\"},\"query\":{\"match\":{\"type\":{\"query\":\"mongodb\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
64 | },
65 | "columns": [
66 | "method",
67 | "type",
68 | "path",
69 | "responsetime",
70 | "status",
71 | "query"
72 | ]
73 | }
74 | },
75 | {
76 | "_id": "Errors",
77 | "_type": "search",
78 | "_source": {
79 | "sort": [
80 | "@timestamp",
81 | "desc"
82 | ],
83 | "hits": 0,
84 | "description": "",
85 | "title": "Errors",
86 | "version": 1,
87 | "kibanaSavedObjectMeta": {
88 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":true,\"key\":\"status\",\"value\":\"OK\",\"disabled\":false},\"query\":{\"match\":{\"status\":{\"query\":\"OK\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
89 | },
90 | "columns": [
91 | "type",
92 | "method",
93 | "path",
94 | "responsetime",
95 | "status"
96 | ]
97 | }
98 | },
99 | {
100 | "_id": "Filesystem-stats",
101 | "_type": "search",
102 | "_source": {
103 | "sort": [
104 | "@timestamp",
105 | "desc"
106 | ],
107 | "hits": 0,
108 | "description": "",
109 | "title": "Filesystem stats",
110 | "version": 1,
111 | "kibanaSavedObjectMeta": {
112 | "searchSourceJSON": "{\"index\":\"[topbeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"type: filesystem\",\"analyze_wildcard\":true}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"filter\":[]}"
113 | },
114 | "columns": [
115 | "_source"
116 | ]
117 | }
118 | },
119 | {
120 | "_id": "HTTP-errors",
121 | "_type": "search",
122 | "_source": {
123 | "sort": [
124 | "@timestamp",
125 | "desc"
126 | ],
127 | "hits": 0,
128 | "description": "",
129 | "title": "HTTP errors",
130 | "version": 1,
131 | "kibanaSavedObjectMeta": {
132 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"http\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"http\",\"type\":\"phrase\"}}}},{\"meta\":{\"negate\":true,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"http.code\",\"value\":200,\"disabled\":false},\"query\":{\"match\":{\"http.code\":{\"query\":200,\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}}}"
133 | },
134 | "columns": [
135 | "type",
136 | "method",
137 | "path",
138 | "responsetime",
139 | "status"
140 | ]
141 | }
142 | },
143 | {
144 | "_id": "MongoDB-errors",
145 | "_type": "search",
146 | "_source": {
147 | "sort": [
148 | "@timestamp",
149 | "desc"
150 | ],
151 | "hits": 0,
152 | "description": "",
153 | "title": "MongoDB errors",
154 | "version": 1,
155 | "kibanaSavedObjectMeta": {
156 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"mongodb\"},\"query\":{\"match\":{\"type\":{\"query\":\"mongodb\",\"type\":\"phrase\"}}}},{\"meta\":{\"negate\":true,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"status\",\"value\":\"OK\",\"disabled\":false},\"query\":{\"match\":{\"status\":{\"query\":\"OK\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
157 | },
158 | "columns": [
159 | "method",
160 | "type",
161 | "path",
162 | "responsetime",
163 | "status",
164 | "query"
165 | ]
166 | }
167 | },
168 | {
169 | "_id": "MongoDB-transactions",
170 | "_type": "search",
171 | "_source": {
172 | "sort": [
173 | "@timestamp",
174 | "desc"
175 | ],
176 | "hits": 0,
177 | "description": "",
178 | "title": "MongoDB transactions",
179 | "version": 1,
180 | "kibanaSavedObjectMeta": {
181 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"mongodb\"},\"query\":{\"match\":{\"type\":{\"query\":\"mongodb\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
182 | },
183 | "columns": [
184 | "method",
185 | "type",
186 | "path",
187 | "responsetime",
188 | "status",
189 | "query"
190 | ]
191 | }
192 | },
193 | {
194 | "_id": "MongoDB-transactions-with-write-concern-0",
195 | "_type": "search",
196 | "_source": {
197 | "sort": [
198 | "@timestamp",
199 | "desc"
200 | ],
201 | "hits": 0,
202 | "description": "",
203 | "title": "MongoDB transactions with write concern 0",
204 | "version": 1,
205 | "kibanaSavedObjectMeta": {
206 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"mongodb\"},\"query\":{\"match\":{\"type\":{\"query\":\"mongodb\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"request: \\\"writeConcern w 0\\\"\"}}}"
207 | },
208 | "columns": [
209 | "method",
210 | "type",
211 | "path",
212 | "responsetime",
213 | "status",
214 | "query"
215 | ]
216 | }
217 | },
218 | {
219 | "_id": "MySQL-errors",
220 | "_type": "search",
221 | "_source": {
222 | "sort": [
223 | "@timestamp",
224 | "desc"
225 | ],
226 | "hits": 0,
227 | "description": "",
228 | "title": "MySQL errors",
229 | "version": 1,
230 | "kibanaSavedObjectMeta": {
231 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"mysql\"},\"query\":{\"match\":{\"type\":{\"query\":\"mysql\",\"type\":\"phrase\"}}}},{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":true,\"key\":\"status\",\"value\":\"OK\",\"disabled\":false},\"query\":{\"match\":{\"status\":{\"query\":\"OK\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}}}"
232 | },
233 | "columns": [
234 | "method",
235 | "type",
236 | "path",
237 | "responsetime",
238 | "status"
239 | ]
240 | }
241 | },
242 | {
243 | "_id": "MySQL-Transactions",
244 | "_type": "search",
245 | "_source": {
246 | "sort": [
247 | "@timestamp",
248 | "desc"
249 | ],
250 | "hits": 0,
251 | "description": "",
252 | "title": "MySQL Transactions",
253 | "version": 1,
254 | "kibanaSavedObjectMeta": {
255 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"mysql\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"mysql\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}}}"
256 | },
257 | "columns": [
258 | "method",
259 | "type",
260 | "path",
261 | "responsetime",
262 | "status"
263 | ]
264 | }
265 | },
266 | {
267 | "_id": "PgSQL-errors",
268 | "_type": "search",
269 | "_source": {
270 | "sort": [
271 | "@timestamp",
272 | "desc"
273 | ],
274 | "hits": 0,
275 | "description": "",
276 | "title": "PgSQL errors",
277 | "version": 1,
278 | "kibanaSavedObjectMeta": {
279 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"pgsql\"},\"query\":{\"match\":{\"type\":{\"query\":\"pgsql\",\"type\":\"phrase\"}}}},{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":true,\"key\":\"status\",\"value\":\"OK\",\"disabled\":false},\"query\":{\"match\":{\"status\":{\"query\":\"OK\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
280 | },
281 | "columns": [
282 | "method",
283 | "type",
284 | "path",
285 | "responsetime",
286 | "status"
287 | ]
288 | }
289 | },
290 | {
291 | "_id": "PgSQL-transactions",
292 | "_type": "search",
293 | "_source": {
294 | "sort": [
295 | "@timestamp",
296 | "desc"
297 | ],
298 | "hits": 0,
299 | "description": "",
300 | "title": "PgSQL transactions",
301 | "version": 1,
302 | "kibanaSavedObjectMeta": {
303 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"pgsql\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"pgsql\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
304 | },
305 | "columns": [
306 | "method",
307 | "type",
308 | "path",
309 | "responsetime",
310 | "status"
311 | ]
312 | }
313 | },
314 | {
315 | "_id": "Processes",
316 | "_type": "search",
317 | "_source": {
318 | "sort": [
319 | "@timestamp",
320 | "desc"
321 | ],
322 | "hits": 0,
323 | "description": "",
324 | "title": "Processes",
325 | "version": 1,
326 | "kibanaSavedObjectMeta": {
327 | "searchSourceJSON": "{\"index\":\"[topbeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[{\"meta\":{\"negate\":false,\"index\":\"[topbeat-]YYYY.MM.DD\",\"key\":\"type\",\"value\":\"proc\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"proc\",\"type\":\"phrase\"}}}}]}"
328 | },
329 | "columns": [
330 | "proc.name",
331 | "proc.cpu.user_p",
332 | "proc.mem.rss_p",
333 | "proc.mem.rss",
334 | "proc.state",
335 | "proc.cpu.start_time"
336 | ]
337 | }
338 | },
339 | {
340 | "_id": "Proc-stats",
341 | "_type": "search",
342 | "_source": {
343 | "sort": [
344 | "@timestamp",
345 | "desc"
346 | ],
347 | "hits": 0,
348 | "description": "",
349 | "title": "Proc stats",
350 | "version": 1,
351 | "kibanaSavedObjectMeta": {
352 | "searchSourceJSON": "{\"index\":\"[topbeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"type: process\",\"analyze_wildcard\":true}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"filter\":[]}"
353 | },
354 | "columns": [
355 | "_source"
356 | ]
357 | }
358 | },
359 | {
360 | "_id": "RPC-transactions",
361 | "_type": "search",
362 | "_source": {
363 | "sort": [
364 | "@timestamp",
365 | "desc"
366 | ],
367 | "hits": 0,
368 | "description": "",
369 | "title": "RPC transactions",
370 | "version": 1,
371 | "kibanaSavedObjectMeta": {
372 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[],\"query\":{\"query_string\":{\"query\":\"type: thrift\",\"analyze_wildcard\":true}}}"
373 | },
374 | "columns": [
375 | "type",
376 | "method",
377 | "path",
378 | "responsetime",
379 | "status"
380 | ]
381 | }
382 | },
383 | {
384 | "_id": "System-stats",
385 | "_type": "search",
386 | "_source": {
387 | "sort": [
388 | "@timestamp",
389 | "desc"
390 | ],
391 | "hits": 0,
392 | "description": "",
393 | "title": "System stats",
394 | "version": 1,
395 | "kibanaSavedObjectMeta": {
396 | "searchSourceJSON": "{\"index\":\"[topbeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"type: system\",\"analyze_wildcard\":true}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"filter\":[]}"
397 | },
398 | "columns": [
399 | "_source"
400 | ]
401 | }
402 | },
403 | {
404 | "_id": "System-wide",
405 | "_type": "search",
406 | "_source": {
407 | "sort": [
408 | "@timestamp",
409 | "desc"
410 | ],
411 | "hits": 0,
412 | "description": "",
413 | "title": "System wide",
414 | "version": 1,
415 | "kibanaSavedObjectMeta": {
416 | "searchSourceJSON": "{\"index\":\"[topbeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"fragment_size\":2147483647},\"filter\":[{\"meta\":{\"negate\":false,\"index\":\"[topbeat-]YYYY.MM.DD\",\"key\":\"type\",\"value\":\"system\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"system\",\"type\":\"phrase\"}}}}]}"
417 | },
418 | "columns": [
419 | "beat.name",
420 | "cpu.user_p",
421 | "cpu.steal",
422 | "load.load1",
423 | "load.load5",
424 | "mem.used",
425 | "mem.used_p"
426 | ]
427 | }
428 | },
429 | {
430 | "_id": "Thrift-errors",
431 | "_type": "search",
432 | "_source": {
433 | "sort": [
434 | "@timestamp",
435 | "desc"
436 | ],
437 | "hits": 0,
438 | "description": "",
439 | "title": "Thrift errors",
440 | "version": 1,
441 | "kibanaSavedObjectMeta": {
442 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"disabled\":false,\"index\":\"[packetbeat-]YYYY.MM.DD\",\"key\":\"type\",\"negate\":false,\"value\":\"thrift\"},\"query\":{\"match\":{\"type\":{\"query\":\"thrift\",\"type\":\"phrase\"}}}},{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":true,\"key\":\"status\",\"value\":\"OK\",\"disabled\":false},\"query\":{\"match\":{\"status\":{\"query\":\"OK\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"type: thrift\"}}}"
443 | },
444 | "columns": [
445 | "method",
446 | "type",
447 | "path",
448 | "responsetime",
449 | "status"
450 | ]
451 | }
452 | },
453 | {
454 | "_id": "Thrift-transactions",
455 | "_type": "search",
456 | "_source": {
457 | "sort": [
458 | "@timestamp",
459 | "desc"
460 | ],
461 | "hits": 0,
462 | "description": "",
463 | "title": "Thrift transactions",
464 | "version": 1,
465 | "kibanaSavedObjectMeta": {
466 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"thrift\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"thrift\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"type: thrift\"}}}"
467 | },
468 | "columns": [
469 | "method",
470 | "type",
471 | "path",
472 | "responsetime",
473 | "status"
474 | ]
475 | }
476 | },
477 | {
478 | "_id": "Web-transactions",
479 | "_type": "search",
480 | "_source": {
481 | "sort": [
482 | "@timestamp",
483 | "desc"
484 | ],
485 | "hits": 0,
486 | "description": "",
487 | "title": "Web transactions",
488 | "version": 1,
489 | "kibanaSavedObjectMeta": {
490 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"http\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"http\",\"type\":\"phrase\"}}}}],\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}}}"
491 | },
492 | "columns": [
493 | "type",
494 | "method",
495 | "path",
496 | "responsetime",
497 | "status"
498 | ]
499 | }
500 | },
501 | {
502 | "_id": "NXLog:-Windows-Software:-Installation-and-Updates",
503 | "_type": "search",
504 | "_source": {
505 | "title": "NXLog: Windows Software: Installation and Updates",
506 | "description": "",
507 | "hits": 0,
508 | "columns": [
509 | "_source"
510 | ],
511 | "sort": [
512 | "@timestamp",
513 | "desc"
514 | ],
515 | "version": 1,
516 | "kibanaSavedObjectMeta": {
517 | "searchSourceJSON": "{\"index\":\"logstash-*\",\"filter\":[],\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"query\":{\"query_string\":{\"query\":\"tags:tcp_json_windows AND \\\"Installation Successful\\\"\",\"analyze_wildcard\":true}}}"
518 | }
519 | }
520 | },
521 | {
522 | "_id": "OSSEC:-Changed-File-(Linux)",
523 | "_type": "search",
524 | "_source": {
525 | "title": "OSSEC: Changed File (Linux)",
526 | "description": "",
527 | "hits": 0,
528 | "columns": [
529 | "ossec_modified_file",
530 | "ossec_host_fqdn",
531 | "Details"
532 | ],
533 | "sort": [
534 | "@timestamp",
535 | "desc"
536 | ],
537 | "version": 1,
538 | "kibanaSavedObjectMeta": {
539 | "searchSourceJSON": "{\"index\":\"logstash-*\",\"filter\":[],\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"query\":{\"query_string\":{\"query\":\"\\\"Integrity checksum changed\\\"\",\"analyze_wildcard\":true}}}"
540 | }
541 | }
542 | },
543 | {
544 | "_id": "OSSEC:-All-Alerts",
545 | "_type": "search",
546 | "_source": {
547 | "title": "OSSEC: All Alerts",
548 | "description": "",
549 | "hits": 0,
550 | "columns": [
551 | "Alert_Level",
552 | "ossec_host_fqdn",
553 | "ossec_host_ip",
554 | "Src_IP",
555 | "Description",
556 | "Rule"
557 | ],
558 | "sort": [
559 | "@timestamp",
560 | "desc"
561 | ],
562 | "version": 1,
563 | "kibanaSavedObjectMeta": {
564 | "searchSourceJSON": "{\"index\":\"logstash-*\",\"filter\":[],\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"query\":{\"query_string\":{\"query\":\"* -(iam-shb-*)\",\"analyze_wildcard\":true}}}"
565 | }
566 | }
567 | },
568 | {
569 | "_id": "OSSEC-General-Search",
570 | "_type": "search",
571 | "_source": {
572 | "title": "OSSEC - General Search",
573 | "description": "",
574 | "hits": 0,
575 | "columns": [
576 | "Alert_Level",
577 | "ossec_host_fqdn",
578 | "ossec_host_ip",
579 | "Details"
580 | ],
581 | "sort": [
582 | "@timestamp",
583 | "desc"
584 | ],
585 | "version": 1,
586 | "kibanaSavedObjectMeta": {
587 | "searchSourceJSON": "{\"index\":\"logstash-*\",\"filter\":[],\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647},\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}}}"
588 | }
589 | }
590 | },
591 | {
592 | "_id": "Linux:-User-and-Group-Events",
593 | "_type": "search",
594 | "_source": {
595 | "title": "Linux: User and Group Events",
596 | "description": "",
597 | "hits": 0,
598 | "columns": [
599 | "pam_username",
600 | "tags",
601 | "pam_message",
602 | "message"
603 | ],
604 | "sort": [
605 | "@timestamp",
606 | "desc"
607 | ],
608 | "version": 1,
609 | "kibanaSavedObjectMeta": {
610 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_new_group\\\" tags:\\\"linux_new_user\\\" tags:\\\"linux_password_changed\\\" tags:\\\"linux_delete_user\\\" tags:\\\"linux_removed_group\\\"\",\"analyze_wildcard\":true}},\"filter\":[],\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647}}"
611 | }
612 | }
613 | },
614 | {
615 | "_id": "UCLA-Netflow",
616 | "_type": "search",
617 | "_source": {
618 | "title": "UCLA Netflow",
619 | "description": "",
620 | "hits": 0,
621 | "columns": [
622 | "netflow.in_bytes",
623 | "netflow.ipv4_src_addr",
624 | "netflow.ipv4_dst_addr",
625 | "tags",
626 | "netflow.l4_src_port",
627 | "netflow.l4_dst_port",
628 | "src_geoip.country_name",
629 | "dst_geoip.country_name"
630 | ],
631 | "sort": [
632 | "netflow.in_bytes",
633 | "desc"
634 | ],
635 | "version": 1,
636 | "kibanaSavedObjectMeta": {
637 | "searchSourceJSON": "{\"index\":\"logstash-*\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"tags:src_ucla_* tags:dst_ucla_*\"}},\"filter\":[],\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}},\"require_field_match\":false,\"fragment_size\":2147483647}}"
638 | }
639 | }
640 | }
641 | ]
--------------------------------------------------------------------------------
/kibana-visualizations.json:
--------------------------------------------------------------------------------
1 | [
2 | {
3 | "_id": "CPU-usage-per-process",
4 | "_type": "visualization",
5 | "_source": {
6 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":false,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.cpu.user_p\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"proc.name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
7 | "description": "",
8 | "title": "CPU usage per process",
9 | "version": 1,
10 | "savedSearchId": "Proc-stats",
11 | "kibanaSavedObjectMeta": {
12 | "searchSourceJSON": "{\"filter\":[]}"
13 | }
14 | }
15 | },
16 | {
17 | "_id": "DB-transactions",
18 | "_type": "visualization",
19 | "_source": {
20 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"type\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
21 | "description": "",
22 | "title": "DB transactions",
23 | "version": 1,
24 | "savedSearchId": "DB-transactions",
25 | "kibanaSavedObjectMeta": {
26 | "searchSourceJSON": "{\"filter\":[]}"
27 | }
28 | }
29 | },
30 | {
31 | "_id": "Disk-usage",
32 | "_type": "visualization",
33 | "_source": {
34 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"fs.used\"}},{\"id\":\"2\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"fs.used_p\"}},{\"id\":\"3\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"fs.total\"}},{\"id\":\"4\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"fs.free\"}},{\"id\":\"5\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"fs.free\"}},{\"id\":\"6\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"fs.device_name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"7\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"fs.mount_point\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
35 | "description": "",
36 | "title": "Disk usage",
37 | "version": 1,
38 | "savedSearchId": "Filesystem-stats",
39 | "kibanaSavedObjectMeta": {
40 | "searchSourceJSON": "{\"filter\":[]}"
41 | }
42 | }
43 | },
44 | {
45 | "_id": "Disk-usage-overview",
46 | "_type": "visualization",
47 | "_source": {
48 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"scale\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"fs.used_p\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"beat.name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
49 | "description": "",
50 | "title": "Disk usage overview",
51 | "version": 1,
52 | "savedSearchId": "Filesystem-stats",
53 | "kibanaSavedObjectMeta": {
54 | "searchSourceJSON": "{\"filter\":[]}"
55 | }
56 | }
57 | },
58 | {
59 | "_id": "Errors-count-over-time",
60 | "_type": "visualization",
61 | "_source": {
62 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"type\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
63 | "description": "",
64 | "title": "Errors count over time",
65 | "version": 1,
66 | "savedSearchId": "Errors",
67 | "kibanaSavedObjectMeta": {
68 | "searchSourceJSON": "{\"filter\":[]}"
69 | }
70 | }
71 | },
72 | {
73 | "_id": "Errors-vs-successful-transactions",
74 | "_type": "visualization",
75 | "_source": {
76 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"percentage\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"status\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
77 | "kibanaSavedObjectMeta": {
78 | "searchSourceJSON": "{\"filter\":[],\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}}}"
79 | },
80 | "version": 1,
81 | "description": "",
82 | "title": "Errors vs successful transactions"
83 | }
84 | },
85 | {
86 | "_id": "Evolution-of-the-CPU-times-per-process",
87 | "_type": "visualization",
88 | "_source": {
89 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":false,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.cpu.user_p\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"s\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"proc.name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
90 | "description": "",
91 | "title": "Evolution of the CPU times per process",
92 | "version": 1,
93 | "savedSearchId": "Processes",
94 | "kibanaSavedObjectMeta": {
95 | "searchSourceJSON": "{\"filter\":[]}"
96 | }
97 | }
98 | },
99 | {
100 | "_id": "HTTP-codes-for-the-top-queries",
101 | "_type": "visualization",
102 | "_source": {
103 | "visState": "{\"type\":\"pie\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"isDonut\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"split\",\"params\":{\"field\":\"query\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\",\"row\":false}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"http.code\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
104 | "description": "",
105 | "title": "HTTP codes for the top queries",
106 | "version": 1,
107 | "savedSearchId": "Web-transactions",
108 | "kibanaSavedObjectMeta": {
109 | "searchSourceJSON": "{\"filter\":[]}"
110 | }
111 | }
112 | },
113 | {
114 | "_id": "HTTP-error-codes-evolution",
115 | "_type": "visualization",
116 | "_source": {
117 | "visState": "{\"aggs\":[{\"id\":\"1\",\"params\":{\"field\":\"count\"},\"schema\":\"metric\",\"type\":\"sum\"},{\"id\":\"2\",\"params\":{\"extended_bounds\":{},\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1},\"schema\":\"segment\",\"type\":\"date_histogram\"},{\"id\":\"3\",\"params\":{\"field\":\"http.code\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":5},\"schema\":\"group\",\"type\":\"terms\"}],\"listeners\":{},\"params\":{\"addLegend\":true,\"addTooltip\":true,\"defaultYExtents\":false,\"shareYAxis\":true},\"type\":\"line\"}",
118 | "kibanaSavedObjectMeta": {
119 | "searchSourceJSON": "{\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"http\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"http\",\"type\":\"phrase\"}}}}],\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"query\":{\"query_string\":{\"query\":\"!http.code: [200 TO 299]\",\"analyze_wildcard\":true}}}"
120 | },
121 | "version": 1,
122 | "description": "",
123 | "title": "HTTP error codes evolution"
124 | }
125 | },
126 | {
127 | "_id": "HTTP-error-codes",
128 | "_type": "visualization",
129 | "_source": {
130 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"http.code\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
131 | "kibanaSavedObjectMeta": {
132 | "searchSourceJSON": "{\"filter\":[{\"meta\":{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"negate\":false,\"key\":\"type\",\"value\":\"http\",\"disabled\":false},\"query\":{\"match\":{\"type\":{\"query\":\"http\",\"type\":\"phrase\"}}}}],\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"query\":{\"query_string\":{\"query\":\"http.code: [300 TO *]\",\"analyze_wildcard\":true}}}"
133 | },
134 | "version": 1,
135 | "description": "",
136 | "title": "HTTP error codes"
137 | }
138 | },
139 | {
140 | "_id": "Latency-histogram",
141 | "_type": "visualization",
142 | "_source": {
143 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"responsetime\",\"interval\":10,\"min_doc_count\":false,\"extended_bounds\":{}}}],\"listeners\":{}}",
144 | "kibanaSavedObjectMeta": {
145 | "searchSourceJSON": "{\"index\":\"[packetbeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"*\",\"analyze_wildcard\":true}},\"filter\":[]}"
146 | },
147 | "version": 1,
148 | "description": "",
149 | "title": "Latency histogram"
150 | }
151 | },
152 | {
153 | "_id": "Memory-usage",
154 | "_type": "visualization",
155 | "_source": {
156 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":false,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"mem.used_p\"}},{\"id\":\"2\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"swap.used_p\"}},{\"id\":\"3\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
157 | "description": "",
158 | "title": "Memory usage",
159 | "version": 1,
160 | "savedSearchId": "System-stats",
161 | "kibanaSavedObjectMeta": {
162 | "searchSourceJSON": "{\"filter\":[]}"
163 | }
164 | }
165 | },
166 | {
167 | "_id": "Memory-usage-per-process",
168 | "_type": "visualization",
169 | "_source": {
170 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":false,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.mem.rss_p\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"proc.name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
171 | "description": "",
172 | "title": "Memory usage per process",
173 | "version": 1,
174 | "savedSearchId": "Proc-stats",
175 | "kibanaSavedObjectMeta": {
176 | "searchSourceJSON": "{\"filter\":[]}"
177 | }
178 | }
179 | },
180 | {
181 | "_id": "MongoDB-commands",
182 | "_type": "visualization",
183 | "_source": {
184 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":true,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"silhouette\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"method\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
185 | "description": "",
186 | "title": "MongoDB commands",
187 | "version": 1,
188 | "savedSearchId": "MongoDB-transactions",
189 | "kibanaSavedObjectMeta": {
190 | "searchSourceJSON": "{\"filter\":[]}"
191 | }
192 | }
193 | },
194 | {
195 | "_id": "MongoDB-errors",
196 | "_type": "visualization",
197 | "_source": {
198 | "visState": "{\"type\":\"line\",\"params\":{\"addLegend\":true,\"addTimeMarker\":false,\"addTooltip\":true,\"defaultYExtents\":false,\"drawLinesBetweenPoints\":true,\"interpolate\":\"linear\",\"radiusRatio\":9,\"scale\":\"linear\",\"setYExtents\":false,\"shareYAxis\":true,\"showCircles\":true,\"smoothLines\":false,\"spyPerPage\":10,\"times\":[],\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"split\",\"params\":{\"field\":\"resource\",\"size\":3,\"order\":\"desc\",\"orderBy\":\"1\",\"row\":true}},{\"id\":\"4\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"method\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
199 | "description": "",
200 | "title": "MongoDB errors",
201 | "version": 1,
202 | "savedSearchId": "MongoDB-errors",
203 | "kibanaSavedObjectMeta": {
204 | "searchSourceJSON": "{\"filter\":[]}"
205 | }
206 | }
207 | },
208 | {
209 | "_id": "MongoDB-errors-per-collection",
210 | "_type": "visualization",
211 | "_source": {
212 | "visState": "{\"type\":\"line\",\"params\":{\"addLegend\":true,\"addTimeMarker\":false,\"addTooltip\":true,\"defaultYExtents\":false,\"drawLinesBetweenPoints\":true,\"interpolate\":\"linear\",\"radiusRatio\":9,\"scale\":\"linear\",\"setYExtents\":false,\"shareYAxis\":true,\"showCircles\":true,\"smoothLines\":false,\"spyPerPage\":10,\"times\":[],\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"resource\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
213 | "description": "",
214 | "title": "MongoDB errors per collection",
215 | "version": 1,
216 | "savedSearchId": "MongoDB-errors",
217 | "kibanaSavedObjectMeta": {
218 | "searchSourceJSON": "{\"filter\":[]}"
219 | }
220 | }
221 | },
222 | {
223 | "_id": "MongoDB-in-slash-out-throughput",
224 | "_type": "visualization",
225 | "_source": {
226 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"showCircles\":true,\"smoothLines\":false,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":true,\"radiusRatio\":9,\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"bytes_in\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"4\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"bytes_out\"}}],\"listeners\":{}}",
227 | "description": "",
228 | "title": "MongoDB in/out throughput",
229 | "version": 1,
230 | "savedSearchId": "MongoDB-transactions",
231 | "kibanaSavedObjectMeta": {
232 | "searchSourceJSON": "{\"filter\":[]}"
233 | }
234 | }
235 | },
236 | {
237 | "_id": "MongoDB-response-times-and-count",
238 | "_type": "visualization",
239 | "_source": {
240 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"showCircles\":true,\"smoothLines\":false,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":false,\"radiusRatio\":\"9\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"percentiles\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\",\"percents\":[99]}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"resource\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1.99\"}},{\"id\":\"4\",\"type\":\"sum\",\"schema\":\"radius\",\"params\":{\"field\":\"count\"}}],\"listeners\":{}}",
241 | "description": "",
242 | "title": "MongoDB response times and count",
243 | "version": 1,
244 | "savedSearchId": "MongoDB-transactions",
245 | "kibanaSavedObjectMeta": {
246 | "searchSourceJSON": "{\"filter\":[]}"
247 | }
248 | }
249 | },
250 | {
251 | "_id": "MongoDB-response-times-by-collection",
252 | "_type": "visualization",
253 | "_source": {
254 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"showCircles\":true,\"smoothLines\":false,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":false,\"radiusRatio\":\"9\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"percentiles\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\",\"percents\":[99]}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"resource\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1.99\"}},{\"id\":\"4\",\"type\":\"sum\",\"schema\":\"radius\",\"params\":{\"field\":\"count\"}}],\"listeners\":{}}",
255 | "description": "",
256 | "title": "MongoDB response times by collection",
257 | "version": 1,
258 | "savedSearchId": "MongoDB-transactions",
259 | "kibanaSavedObjectMeta": {
260 | "searchSourceJSON": "{\"filter\":[]}"
261 | }
262 | }
263 | },
264 | {
265 | "_id": "Most-frequent-MySQL-queries",
266 | "_type": "visualization",
267 | "_source": {
268 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"query\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
269 | "description": "",
270 | "title": "Most frequent MySQL queries",
271 | "version": 1,
272 | "savedSearchId": "MySQL-Transactions",
273 | "kibanaSavedObjectMeta": {
274 | "searchSourceJSON": "{\"filter\":[]}"
275 | }
276 | }
277 | },
278 | {
279 | "_id": "Most-frequent-PgSQL-queries",
280 | "_type": "visualization",
281 | "_source": {
282 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"query\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
283 | "description": "",
284 | "title": "Most frequent PgSQL queries",
285 | "version": 1,
286 | "savedSearchId": "PgSQL-transactions",
287 | "kibanaSavedObjectMeta": {
288 | "searchSourceJSON": "{\"filter\":[]}"
289 | }
290 | }
291 | },
292 | {
293 | "_id": "MySQL-Errors",
294 | "_type": "visualization",
295 | "_source": {
296 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
297 | "description": "",
298 | "title": "MySQL Errors",
299 | "version": 1,
300 | "savedSearchId": "MySQL-errors",
301 | "kibanaSavedObjectMeta": {
302 | "searchSourceJSON": "{\"filter\":[]}"
303 | }
304 | }
305 | },
306 | {
307 | "_id": "MySQL-Methods",
308 | "_type": "visualization",
309 | "_source": {
310 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"wiggle\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"method\",\"size\":20,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
311 | "description": "",
312 | "title": "MySQL Methods",
313 | "version": 1,
314 | "savedSearchId": "MySQL-Transactions",
315 | "kibanaSavedObjectMeta": {
316 | "searchSourceJSON": "{\"filter\":[]}"
317 | }
318 | }
319 | },
320 | {
321 | "_id": "MySQL-Reads-vs-Writes",
322 | "_type": "visualization",
323 | "_source": {
324 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"filters\",\"schema\":\"group\",\"params\":{\"filters\":[{\"input\":{\"query\":{\"query_string\":{\"query\":\"method: SELECT\",\"analyze_wildcard\":true}}}},{\"input\":{\"query\":{\"query_string\":{\"query\":\"method: INSERT or method: UPDATE or method: DELETE\",\"analyze_wildcard\":true}}}}]}}],\"listeners\":{}}",
325 | "description": "",
326 | "title": "MySQL Reads vs Writes",
327 | "version": 1,
328 | "savedSearchId": "MySQL-Transactions",
329 | "kibanaSavedObjectMeta": {
330 | "searchSourceJSON": "{\"filter\":[]}"
331 | }
332 | }
333 | },
334 | {
335 | "_id": "Mysql-response-times-percentiles",
336 | "_type": "visualization",
337 | "_source": {
338 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"percentiles\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\",\"percents\":[75,99,99.5]}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
339 | "description": "",
340 | "title": "Mysql response times percentiles",
341 | "version": 1,
342 | "savedSearchId": "MySQL-Transactions",
343 | "kibanaSavedObjectMeta": {
344 | "searchSourceJSON": "{\"filter\":[]}"
345 | }
346 | }
347 | },
348 | {
349 | "_id": "MySQL-throughput",
350 | "_type": "visualization",
351 | "_source": {
352 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"bytes_out\"}},{\"id\":\"3\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"bytes_in\"}},{\"id\":\"4\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
353 | "description": "",
354 | "title": "MySQL throughput",
355 | "version": 1,
356 | "savedSearchId": "MySQL-Transactions",
357 | "kibanaSavedObjectMeta": {
358 | "searchSourceJSON": "{\"filter\":[]}"
359 | }
360 | }
361 | },
362 | {
363 | "_id": "Navigation",
364 | "_type": "visualization",
365 | "_source": {
366 | "visState": "{\"aggs\":[],\"listeners\":{},\"params\":{\"markdown\":\"###Packetbeat:\\n\\n[Dashboard](/#/dashboard/Packetbeat-Dashboard)\\n\\n[Web transactions](/#/dashboard/HTTP)\\n\\n[MySQL performance](/#/dashboard/MySQL-performance)\\n\\n[PostgreSQL performance](/#/dashboard/PgSQL-performance)\\n\\n[MongoDB performance](/#/dashboard/MongoDB-performance)\\n\\n[Thrift-RPC performance](/#/dashboard/Thrift-performance)\\n\\n###Topbeat:\\n\\n[Dashboard](/#/dashboard/Topbeat-Dashboard)\"},\"type\":\"markdown\"}",
367 | "kibanaSavedObjectMeta": {
368 | "searchSourceJSON": "{\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}},\"filter\":[]}"
369 | },
370 | "version": 1,
371 | "description": "",
372 | "title": "Navigation"
373 | }
374 | },
375 | {
376 | "_id": "Number-of-MongoDB-transactions-with-writeConcern-w-equal-0",
377 | "_type": "visualization",
378 | "_source": {
379 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"showCircles\":true,\"smoothLines\":false,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":true,\"radiusRatio\":9,\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"count\",\"schema\":\"radius\",\"params\":{}}],\"listeners\":{}}",
380 | "description": "",
381 | "title": "Number of MongoDB transactions with writeConcern w=0",
382 | "version": 1,
383 | "savedSearchId": "MongoDB-transactions-with-write-concern-0",
384 | "kibanaSavedObjectMeta": {
385 | "searchSourceJSON": "{\"filter\":[]}"
386 | }
387 | }
388 | },
389 | {
390 | "_id": "PgSQL-Errors",
391 | "_type": "visualization",
392 | "_source": {
393 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
394 | "description": "",
395 | "title": "PgSQL Errors",
396 | "version": 1,
397 | "savedSearchId": "PgSQL-errors",
398 | "kibanaSavedObjectMeta": {
399 | "searchSourceJSON": "{\"filter\":[]}"
400 | }
401 | }
402 | },
403 | {
404 | "_id": "PgSQL-Methods",
405 | "_type": "visualization",
406 | "_source": {
407 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"wiggle\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"method\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
408 | "description": "",
409 | "title": "PgSQL Methods",
410 | "version": 1,
411 | "savedSearchId": "PgSQL-transactions",
412 | "kibanaSavedObjectMeta": {
413 | "searchSourceJSON": "{\"filter\":[]}"
414 | }
415 | }
416 | },
417 | {
418 | "_id": "PgSQL-Reads-vs-Writes",
419 | "_type": "visualization",
420 | "_source": {
421 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"filters\",\"schema\":\"group\",\"params\":{\"filters\":[{\"input\":{\"query\":{\"query_string\":{\"query\":\"method: SELECT\",\"analyze_wildcard\":true}}}},{\"input\":{\"query\":{\"query_string\":{\"query\":\"method: INSERT or method: UPDATE or method: DELETE\",\"analyze_wildcard\":true}}}}]}}],\"listeners\":{}}",
422 | "description": "",
423 | "title": "PgSQL Reads vs Writes",
424 | "version": 1,
425 | "savedSearchId": "PgSQL-transactions",
426 | "kibanaSavedObjectMeta": {
427 | "searchSourceJSON": "{\"filter\":[]}"
428 | }
429 | }
430 | },
431 | {
432 | "_id": "PgSQL-response-times-percentiles",
433 | "_type": "visualization",
434 | "_source": {
435 | "visState": "{\"type\":\"line\",\"params\":{\"addLegend\":true,\"addTooltip\":true,\"defaultYExtents\":false,\"shareYAxis\":true},\"aggs\":[{\"id\":\"1\",\"type\":\"percentiles\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\",\"percents\":[75,99,99.5]}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
436 | "description": "",
437 | "title": "PgSQL response times percentiles",
438 | "version": 1,
439 | "savedSearchId": "PgSQL-transactions",
440 | "kibanaSavedObjectMeta": {
441 | "searchSourceJSON": "{\"filter\":[]}"
442 | }
443 | }
444 | },
445 | {
446 | "_id": "PgSQL-throughput",
447 | "_type": "visualization",
448 | "_source": {
449 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"bytes_out\"}},{\"id\":\"2\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"bytes_in\"}},{\"id\":\"3\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
450 | "description": "",
451 | "title": "PgSQL throughput",
452 | "version": 1,
453 | "savedSearchId": "PgSQL-transactions",
454 | "kibanaSavedObjectMeta": {
455 | "searchSourceJSON": "{\"filter\":[]}"
456 | }
457 | }
458 | },
459 | {
460 | "_id": "Process-status",
461 | "_type": "visualization",
462 | "_source": {
463 | "visState": "{\"type\":\"pie\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"isDonut\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"proc.state\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
464 | "description": "",
465 | "title": "Process status",
466 | "version": 1,
467 | "savedSearchId": "Proc-stats",
468 | "kibanaSavedObjectMeta": {
469 | "searchSourceJSON": "{\"filter\":[]}"
470 | }
471 | }
472 | },
473 | {
474 | "_id": "Reads-versus-Writes",
475 | "_type": "visualization",
476 | "_source": {
477 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"grouped\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"filters\",\"schema\":\"group\",\"params\":{\"filters\":[{\"input\":{\"query\":{\"query_string\":{\"query\":\"method: SELECT\",\"analyze_wildcard\":true}}}},{\"input\":{\"query\":{\"query_string\":{\"query\":\"method: INSERT or method: UPDATE or method: DELETE\",\"analyze_wildcard\":true}}}}]}}],\"listeners\":{}}",
478 | "description": "",
479 | "title": "Reads versus Writes",
480 | "version": 1,
481 | "savedSearchId": "MySQL-Transactions",
482 | "kibanaSavedObjectMeta": {
483 | "searchSourceJSON": "{\"filter\":[]}"
484 | }
485 | }
486 | },
487 | {
488 | "_id": "Response-times-percentiles",
489 | "_type": "visualization",
490 | "_source": {
491 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"percentiles\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\",\"percents\":[75,95,99]}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
492 | "kibanaSavedObjectMeta": {
493 | "searchSourceJSON": "{\"filter\":[],\"index\":\"[packetbeat-]YYYY.MM.DD\",\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fields\":{\"*\":{}}},\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"*\"}}}"
494 | },
495 | "version": 1,
496 | "description": "",
497 | "title": "Response times percentiles"
498 | }
499 | },
500 | {
501 | "_id": "Response-times-repartition",
502 | "_type": "visualization",
503 | "_source": {
504 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"histogram\",\"schema\":\"group\",\"params\":{\"field\":\"responsetime\",\"interval\":10,\"extended_bounds\":{}}}],\"listeners\":{}}",
505 | "description": "",
506 | "title": "Response times repartition",
507 | "version": 1,
508 | "savedSearchId": "Default-Search",
509 | "kibanaSavedObjectMeta": {
510 | "searchSourceJSON": "{\"filter\":[]}"
511 | }
512 | }
513 | },
514 | {
515 | "_id": "RPC-transactions",
516 | "_type": "visualization",
517 | "_source": {
518 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
519 | "description": "",
520 | "title": "RPC transactions",
521 | "version": 1,
522 | "savedSearchId": "RPC-transactions",
523 | "kibanaSavedObjectMeta": {
524 | "searchSourceJSON": "{\"filter\":[]}"
525 | }
526 | }
527 | },
528 | {
529 | "_id": "Servers",
530 | "_type": "visualization",
531 | "_source": {
532 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"cpu.user_p\"}},{\"id\":\"3\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"cpu.system_p\"}},{\"id\":\"4\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"mem.total\"}},{\"id\":\"5\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"mem.used\"}},{\"id\":\"8\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"mem.used_p\"}},{\"id\":\"6\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"mem.free\"}},{\"id\":\"9\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"beat.name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
533 | "description": "",
534 | "title": "Servers",
535 | "version": 1,
536 | "savedSearchId": "System-stats",
537 | "kibanaSavedObjectMeta": {
538 | "searchSourceJSON": "{\"filter\":[]}"
539 | }
540 | }
541 | },
542 | {
543 | "_id": "Slowest-MySQL-queries",
544 | "_type": "visualization",
545 | "_source": {
546 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"query\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
547 | "description": "",
548 | "title": "Slowest MySQL queries",
549 | "version": 1,
550 | "savedSearchId": "MySQL-Transactions",
551 | "kibanaSavedObjectMeta": {
552 | "searchSourceJSON": "{\"filter\":[]}"
553 | }
554 | }
555 | },
556 | {
557 | "_id": "Slowest-PgSQL-queries",
558 | "_type": "visualization",
559 | "_source": {
560 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"query\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
561 | "description": "",
562 | "title": "Slowest PgSQL queries",
563 | "version": 1,
564 | "savedSearchId": "PgSQL-transactions",
565 | "kibanaSavedObjectMeta": {
566 | "searchSourceJSON": "{\"filter\":[]}"
567 | }
568 | }
569 | },
570 | {
571 | "_id": "Slowest-Thrift-RPC-methods",
572 | "_type": "visualization",
573 | "_source": {
574 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"method\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
575 | "description": "",
576 | "title": "Slowest Thrift RPC methods",
577 | "version": 1,
578 | "savedSearchId": "Thrift-transactions",
579 | "kibanaSavedObjectMeta": {
580 | "searchSourceJSON": "{\"filter\":[]}"
581 | }
582 | }
583 | },
584 | {
585 | "_id": "System-load",
586 | "_type": "visualization",
587 | "_source": {
588 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"showCircles\":true,\"smoothLines\":false,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":true,\"radiusRatio\":9,\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"load.load1\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"beat.name\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
589 | "description": "",
590 | "title": "System load",
591 | "version": 1,
592 | "savedSearchId": "System-stats",
593 | "kibanaSavedObjectMeta": {
594 | "searchSourceJSON": "{\"filter\":[]}"
595 | }
596 | }
597 | },
598 | {
599 | "_id": "Thrift-requests-per-minute",
600 | "_type": "visualization",
601 | "_source": {
602 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"minute\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
603 | "description": "",
604 | "title": "Thrift requests per minute",
605 | "version": 1,
606 | "savedSearchId": "Thrift-transactions",
607 | "kibanaSavedObjectMeta": {
608 | "searchSourceJSON": "{\"filter\":[]}"
609 | }
610 | }
611 | },
612 | {
613 | "_id": "Thrift-response-times-percentiles",
614 | "_type": "visualization",
615 | "_source": {
616 | "visState": "{\"aggs\":[{\"id\":\"1\",\"params\":{\"field\":\"responsetime\",\"percents\":[75,99,99.5]},\"schema\":\"metric\",\"type\":\"percentiles\"},{\"id\":\"2\",\"params\":{\"extended_bounds\":{},\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1},\"schema\":\"segment\",\"type\":\"date_histogram\"}],\"listeners\":{},\"params\":{\"addLegend\":true,\"addTooltip\":true,\"defaultYExtents\":false,\"shareYAxis\":true},\"type\":\"line\"}",
617 | "description": "",
618 | "title": "Thrift response times percentiles",
619 | "version": 1,
620 | "savedSearchId": "Thrift-transactions",
621 | "kibanaSavedObjectMeta": {
622 | "searchSourceJSON": "{\"filter\":[]}"
623 | }
624 | }
625 | },
626 | {
627 | "_id": "Thrift-RPC-Errors",
628 | "_type": "visualization",
629 | "_source": {
630 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
631 | "description": "",
632 | "title": "Thrift RPC Errors",
633 | "version": 1,
634 | "savedSearchId": "Thrift-errors",
635 | "kibanaSavedObjectMeta": {
636 | "searchSourceJSON": "{\"filter\":[]}"
637 | }
638 | }
639 | },
640 | {
641 | "_id": "Top-10-memory-consumers",
642 | "_type": "visualization",
643 | "_source": {
644 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"scale\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.mem.rss_p\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"proc.name\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
645 | "description": "",
646 | "title": "Top 10 memory consumers",
647 | "version": 1,
648 | "savedSearchId": "Processes",
649 | "kibanaSavedObjectMeta": {
650 | "searchSourceJSON": "{\"filter\":[]}"
651 | }
652 | }
653 | },
654 | {
655 | "_id": "Top-10-processes-by-total-CPU-usage",
656 | "_type": "visualization",
657 | "_source": {
658 | "visState": "{\"aggs\":[{\"id\":\"1\",\"params\":{\"field\":\"proc.cpu.total\"},\"schema\":\"metric\",\"type\":\"max\"},{\"id\":\"2\",\"params\":{\"field\":\"proc.name\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":10},\"schema\":\"segment\",\"type\":\"terms\"}],\"listeners\":{},\"params\":{\"addLegend\":true,\"addTimeMarker\":false,\"addTooltip\":true,\"defaultYExtents\":false,\"mode\":\"stacked\",\"scale\":\"linear\",\"setYExtents\":false,\"shareYAxis\":true,\"times\":[],\"yAxis\":{}},\"type\":\"histogram\"}",
659 | "description": "",
660 | "title": "Top 10 processes by total CPU usage",
661 | "version": 1,
662 | "savedSearchId": "Processes",
663 | "kibanaSavedObjectMeta": {
664 | "searchSourceJSON": "{\"filter\":[]}"
665 | }
666 | }
667 | },
668 | {
669 | "_id": "Top-processes",
670 | "_type": "visualization",
671 | "_source": {
672 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.cpu.user_p\"}},{\"id\":\"2\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.mem.rss\"}},{\"id\":\"3\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.mem.rss_p\"}},{\"id\":\"5\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"proc.mem.share\"}},{\"id\":\"6\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"proc.name\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
673 | "description": "",
674 | "title": "Top processes",
675 | "version": 1,
676 | "savedSearchId": "Proc-stats",
677 | "kibanaSavedObjectMeta": {
678 | "searchSourceJSON": "{\"filter\":[]}"
679 | }
680 | }
681 | },
682 | {
683 | "_id": "Top-slowest-MongoDB-queries",
684 | "_type": "visualization",
685 | "_source": {
686 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"percentiles\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\",\"percents\":[99]}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"query\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1.99\"}}],\"listeners\":{}}",
687 | "description": "",
688 | "title": "Top slowest MongoDB queries",
689 | "version": 1,
690 | "savedSearchId": "MongoDB-transactions",
691 | "kibanaSavedObjectMeta": {
692 | "searchSourceJSON": "{\"filter\":[]}"
693 | }
694 | }
695 | },
696 | {
697 | "_id": "Top-Thrift-RPC-calls-with-errors",
698 | "_type": "visualization",
699 | "_source": {
700 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"method\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
701 | "description": "",
702 | "title": "Top Thrift-RPC calls with errors",
703 | "version": 1,
704 | "savedSearchId": "Thrift-errors",
705 | "kibanaSavedObjectMeta": {
706 | "searchSourceJSON": "{\"filter\":[]}"
707 | }
708 | }
709 | },
710 | {
711 | "_id": "Top-Thrift-RPC-methods",
712 | "_type": "visualization",
713 | "_source": {
714 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"method\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
715 | "description": "",
716 | "title": "Top Thrift-RPC methods",
717 | "version": 1,
718 | "savedSearchId": "Thrift-transactions",
719 | "kibanaSavedObjectMeta": {
720 | "searchSourceJSON": "{\"filter\":[]}"
721 | }
722 | }
723 | },
724 | {
725 | "_id": "Total-number-of-HTTP-transactions",
726 | "_type": "visualization",
727 | "_source": {
728 | "visState": "{\"aggs\":[{\"id\":\"1\",\"params\":{\"field\":\"count\"},\"schema\":\"metric\",\"type\":\"sum\"}],\"listeners\":{},\"params\":{\"fontSize\":\"37\"},\"type\":\"metric\"}",
729 | "description": "",
730 | "title": "Total number of HTTP transactions",
731 | "version": 1,
732 | "savedSearchId": "Web-transactions",
733 | "kibanaSavedObjectMeta": {
734 | "searchSourceJSON": "{\"filter\":[]}"
735 | }
736 | }
737 | },
738 | {
739 | "_id": "Total-time-spent-in-each-MongoDB-collection",
740 | "_type": "visualization",
741 | "_source": {
742 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":false,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"responsetime\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"group\",\"params\":{\"field\":\"resource\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
743 | "description": "",
744 | "title": "Total time spent in each MongoDB collection",
745 | "version": 1,
746 | "savedSearchId": "MongoDB-transactions",
747 | "kibanaSavedObjectMeta": {
748 | "searchSourceJSON": "{\"filter\":[]}"
749 | }
750 | }
751 | },
752 | {
753 | "_id": "Web-transactions",
754 | "_type": "visualization",
755 | "_source": {
756 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
757 | "description": "",
758 | "title": "Web transactions",
759 | "version": 1,
760 | "savedSearchId": "Web-transactions",
761 | "kibanaSavedObjectMeta": {
762 | "searchSourceJSON": "{\"filter\":[]}"
763 | }
764 | }
765 | },
766 | {
767 | "_id": "Average-system-load-across-all-systems",
768 | "_type": "visualization",
769 | "_source": {
770 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"avg\",\"schema\":\"metric\",\"params\":{\"field\":\"load.load1\"}}],\"listeners\":{}}",
771 | "description": "",
772 | "title": "Average system load across all systems",
773 | "version": 1,
774 | "savedSearchId": "System-wide",
775 | "kibanaSavedObjectMeta": {
776 | "searchSourceJSON": "{\"filter\":[]}"
777 | }
778 | }
779 | },
780 | {
781 | "_id": "Cache-transactions",
782 | "_type": "visualization",
783 | "_source": {
784 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":false,\"mode\":\"stacked\",\"defaultYExtents\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
785 | "description": "",
786 | "title": "Cache transactions",
787 | "version": 1,
788 | "savedSearchId": "Cache-transactions",
789 | "kibanaSavedObjectMeta": {
790 | "searchSourceJSON": "{\"filter\":[]}"
791 | }
792 | }
793 | },
794 | {
795 | "_id": "Client-locations",
796 | "_type": "visualization",
797 | "_source": {
798 | "visState": "{\"type\":\"tile_map\",\"params\":{\"isDesaturated\":true,\"mapType\":\"Shaded Circle Markers\"},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"geohash_grid\",\"schema\":\"segment\",\"params\":{\"field\":\"client_location\",\"precision\":3}}],\"listeners\":{}}",
799 | "description": "",
800 | "title": "Client locations",
801 | "version": 1,
802 | "savedSearchId": "Web-transactions",
803 | "kibanaSavedObjectMeta": {
804 | "searchSourceJSON": "{\"filter\":[]}"
805 | }
806 | }
807 | },
808 | {
809 | "_id": "CPU-usage",
810 | "_type": "visualization",
811 | "_source": {
812 | "visState": "{\"type\":\"area\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"smoothLines\":false,\"scale\":\"linear\",\"interpolate\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"cpu.system_p\"}},{\"id\":\"2\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"cpu.user_p\"}},{\"id\":\"3\",\"type\":\"date_histogram\",\"schema\":\"segment\",\"params\":{\"field\":\"@timestamp\",\"interval\":\"auto\",\"customInterval\":\"2h\",\"min_doc_count\":1,\"extended_bounds\":{}}}],\"listeners\":{}}",
813 | "description": "",
814 | "title": "CPU usage",
815 | "version": 1,
816 | "savedSearchId": "System-stats",
817 | "kibanaSavedObjectMeta": {
818 | "searchSourceJSON": "{\"filter\":[]}"
819 | }
820 | }
821 | },
822 | {
823 | "_id": "Top-10-HTTP-requests",
824 | "_type": "visualization",
825 | "_source": {
826 | "title": "Top 10 HTTP requests",
827 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"sum\",\"schema\":\"metric\",\"params\":{\"field\":\"count\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"query\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"client_ip\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"4\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"http.code\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"5\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"method\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"6\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"beat.name\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
828 | "uiStateJSON": "{}",
829 | "description": "",
830 | "savedSearchId": "Web-transactions",
831 | "version": 1,
832 | "kibanaSavedObjectMeta": {
833 | "searchSourceJSON": "{\"filter\":[]}"
834 | }
835 | }
836 | },
837 | {
838 | "_id": "Visualization:-User-and-Group-Events",
839 | "_type": "visualization",
840 | "_source": {
841 | "title": "Visualization: User and Group Events",
842 | "visState": "{\"type\":\"table\",\"params\":{\"perPage\":10,\"showPartialRows\":false,\"showMeticsAtAllLevels\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"5\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"timestamp\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"pam_username\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"3\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"tags\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}},{\"id\":\"4\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"beat.hostname\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"_term\"}},{\"id\":\"6\",\"type\":\"terms\",\"schema\":\"bucket\",\"params\":{\"field\":\"geoip.country_name\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
843 | "uiStateJSON": "{}",
844 | "description": "",
845 | "savedSearchId": "Linux:-User-and-Group-Events",
846 | "version": 1,
847 | "kibanaSavedObjectMeta": {
848 | "searchSourceJSON": "{\"filter\":[]}"
849 | }
850 | }
851 | },
852 | {
853 | "_id": "Visualization:-Linux-(Password-Change)",
854 | "_type": "visualization",
855 | "_source": {
856 | "title": "Visualization: Linux (Password Change)",
857 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
858 | "uiStateJSON": "{}",
859 | "description": "",
860 | "version": 1,
861 | "kibanaSavedObjectMeta": {
862 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_password_changed\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
863 | }
864 | }
865 | },
866 | {
867 | "_id": "Visualization:-Linux-(Group-Deleted)",
868 | "_type": "visualization",
869 | "_source": {
870 | "title": "Visualization: Linux (Group Deleted)",
871 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
872 | "uiStateJSON": "{}",
873 | "description": "",
874 | "version": 1,
875 | "kibanaSavedObjectMeta": {
876 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_password_changed\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
877 | }
878 | }
879 | },
880 | {
881 | "_id": "Visualization:-Linux-(User-Deleted)",
882 | "_type": "visualization",
883 | "_source": {
884 | "title": "Visualization: Linux (User Deleted)",
885 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
886 | "uiStateJSON": "{}",
887 | "description": "",
888 | "version": 1,
889 | "kibanaSavedObjectMeta": {
890 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_password_changed\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
891 | }
892 | }
893 | },
894 | {
895 | "_id": "Visualization:-Linux-(New-Group)",
896 | "_type": "visualization",
897 | "_source": {
898 | "title": "Visualization: Linux (New Group)",
899 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
900 | "uiStateJSON": "{}",
901 | "description": "",
902 | "version": 1,
903 | "kibanaSavedObjectMeta": {
904 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_new_user\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
905 | }
906 | }
907 | },
908 | {
909 | "_id": "Visualization:-Linux-(New-User)",
910 | "_type": "visualization",
911 | "_source": {
912 | "title": "Visualization: Linux (New User)",
913 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
914 | "uiStateJSON": "{}",
915 | "description": "",
916 | "version": 1,
917 | "kibanaSavedObjectMeta": {
918 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_new_user\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
919 | }
920 | }
921 | },
922 | {
923 | "_id": "Linux-(Group-Deleted)",
924 | "_type": "visualization",
925 | "_source": {
926 | "title": "Linux (Group Deleted)",
927 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
928 | "uiStateJSON": "{}",
929 | "description": "",
930 | "version": 1,
931 | "kibanaSavedObjectMeta": {
932 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_removed_group\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
933 | }
934 | }
935 | },
936 | {
937 | "_id": "Linux-(User-Deleted)",
938 | "_type": "visualization",
939 | "_source": {
940 | "title": "Linux (User Deleted)",
941 | "visState": "{\"type\":\"metric\",\"params\":{\"fontSize\":60},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}}],\"listeners\":{}}",
942 | "uiStateJSON": "{}",
943 | "description": "",
944 | "version": 1,
945 | "kibanaSavedObjectMeta": {
946 | "searchSourceJSON": "{\"index\":\"[filebeat-]YYYY.MM.DD\",\"query\":{\"query_string\":{\"query\":\"tags:\\\"linux_delete_user\\\"\",\"analyze_wildcard\":true}},\"filter\":[]}"
947 | }
948 | }
949 | },
950 | {
951 | "_id": "Visualization:-Bar-Chart-(Linux:-User-and-Group-Events)",
952 | "_type": "visualization",
953 | "_source": {
954 | "title": "Visualization: Bar Chart (Linux: User and Group Events)",
955 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"scale\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"tags\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
956 | "uiStateJSON": "{}",
957 | "description": "",
958 | "savedSearchId": "Linux:-User-and-Group-Events",
959 | "version": 1,
960 | "kibanaSavedObjectMeta": {
961 | "searchSourceJSON": "{\"filter\":[]}"
962 | }
963 | }
964 | },
965 | {
966 | "_id": "UCLA-Netflow:-Destination-IP-Count-(Bar-Chart)",
967 | "_type": "visualization",
968 | "_source": {
969 | "title": "UCLA Netflow: Destination IP Count (Bar Chart)",
970 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"scale\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"netflow.ipv4_dst_addr\",\"size\":50,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
971 | "uiStateJSON": "{}",
972 | "description": "",
973 | "savedSearchId": "UCLA-Netflow",
974 | "version": 1,
975 | "kibanaSavedObjectMeta": {
976 | "searchSourceJSON": "{\"filter\":[]}"
977 | }
978 | }
979 | },
980 | {
981 | "_id": "UCLA-Netflow:-Source-IP-Count-(Bar-Chart)",
982 | "_type": "visualization",
983 | "_source": {
984 | "title": "UCLA Netflow: Source IP Count (Bar Chart)",
985 | "visState": "{\"type\":\"histogram\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"scale\":\"linear\",\"mode\":\"stacked\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"netflow.ipv4_src_addr\",\"size\":50,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
986 | "uiStateJSON": "{}",
987 | "description": "",
988 | "savedSearchId": "UCLA-Netflow",
989 | "version": 1,
990 | "kibanaSavedObjectMeta": {
991 | "searchSourceJSON": "{\"filter\":[]}"
992 | }
993 | }
994 | },
995 | {
996 | "_id": "UCLA-Netflow:-Outbound-Traffic-Size-On-Destination-IP",
997 | "_type": "visualization",
998 | "_source": {
999 | "title": "UCLA Netflow: Outbound Traffic Size On Destination IP",
1000 | "visState": "{\"type\":\"line\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"showCircles\":true,\"smoothLines\":false,\"interpolate\":\"linear\",\"scale\":\"linear\",\"drawLinesBetweenPoints\":true,\"radiusRatio\":\"45\",\"times\":[],\"addTimeMarker\":false,\"defaultYExtents\":false,\"setYExtents\":false,\"yAxis\":{}},\"aggs\":[{\"id\":\"1\",\"type\":\"max\",\"schema\":\"metric\",\"params\":{\"field\":\"netflow.in_bytes\"}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"netflow.ipv4_dst_addr\",\"size\":10,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}",
1001 | "uiStateJSON": "{}",
1002 | "description": "",
1003 | "savedSearchId": "UCLA-Netflow",
1004 | "version": 1,
1005 | "kibanaSavedObjectMeta": {
1006 | "searchSourceJSON": "{\"filter\":[]}"
1007 | }
1008 | }
1009 | }
1010 | ]
--------------------------------------------------------------------------------