web-interface.assets.bb8c8232-4868.34a48bf661e1144ff850.js Maven / Gradle / Ivy
"use strict";(()=>{(self.webpackChunkgraylog_web_interface=self.webpackChunkgraylog_web_interface||[]).push([["bb8c8232-4868"],{YkjNA19l:(g,i,e)=>{e.r(i),e.d(i,{default:()=>m});var a=e("Z7aTuO5B"),r=e("IOI9nV80"),_=e("q5MWReSo");const u=JSON.parse('{"id":"graylog-security-views__anomalies","type":"DASHBOARD","title":"Anomalies","summary":"Read Only Anomalies","description":"in development","search_id":"656510c70548c8792779eea6","properties":[],"state":{"ec57fdf4-03b8-4bd6-b436-623c0cfc6111":{"selected_fields":null,"formatting":{"highlighting":[]},"titles":{"tab":{"title":"Anomalies"},"widget":{"81fc0ad4-3cdb-4245-b6fd-e28df25091e7":"High Grade Anomalies","d008bc5c-0038-4c63-aae3-a618437e4a5c":"New Risky Users","f4456ec4-a817-4ee9-83b4-85b3a5c6aede":"Avg Anomaly Score by anomaly_detector_name (Top 15)","f73a902f-a154-4b2d-8a11-e6b98a391a9f":"Avg Anomaly Grade by user_name (Top 15)","f7d4843d-967d-4a93-9b31-54e00b77d040":"Most Risky Users","703da1f8-1172-4bc2-83c1-7221b4334275":"Avg Anomaly Score by user_name (Top 15)","a169fa7b-ea87-42db-8782-d7bf81ee8cf7":"Anomaly Events by Use Case Timechart","d88ffbfe-e585-458b-85fe-c6228d231aff":"Anomaly Overall Stats","undefined":"Total Users With Anomaly Events (copy)","59a1729d-2fe3-4687-a3b8-5c81d84a9bb1":"Users With Anomalies","99ae99e1-87d1-4198-8c94-236fa32c9fc9":"High Grade Anomaly Count","221246ac-a8ec-46a1-840d-769f25d73a3b":"Avg Anomaly Grade by anomaly_detector_name (Top 15)","e6eba87f-c45f-4b51-985c-8b9f39d66070":"Anomaly Events by anomaly_grade","9be8b859-a893-4c48-9ac1-9aa8c176da07":"Anomaly Log Summary","a52d982f-396d-4bdd-9430-02eb29225a49":"Anomaly Events by anomaly_score and user_name","9c6cd4dc-9ea1-4531-8621-01adac92f141":"Anomaly Overall Stats","71069faa-433b-4d2a-b908-5f5585a1e837":"Anomaly Count by user_name (Top 15)","4b6e4eac-539c-4eff-9d44-40b61e079a2f":"Anomaly Count by anomaly_detector_name (Top 15)","68b027f0-6329-4a5b-a3fd-85d008eaaf14":"Anomaly Total Risk Scores Timechart","aa1c8d2f-e385-40eb-94de-a7eed9c07984":"Detectors Reporting","10494c16-95dd-4613-adc3-9bc0ba9a5c26":"Anomaly Confidence by anomaly_detector_name (Top 15)","77d18a13-4b5f-42c1-a13b-b67af5f1ec99":"All Anomaly Event Logs","fd47d65f-5c84-4aca-b2a2-70877dbf84e9":"Anomaly Count","ba47351d-b058-4a45-baa9-f38f61a1d1c2":"Anomaly Events by anomaly_detector_name","c85c1315-69ff-4467-8b87-97aa238b1fcf":"Anomaly Count"}},"widgets":[{"id":"10494c16-95dd-4613-adc3-9bc0ba9a5c26","type":"aggregation","config":{"column_pivots":[{"fields":["anomaly_detector_name"],"type":"values","config":{"limit":0}}],"rollup":false,"row_pivots":[{"fields":["timestamp"],"type":"time","config":{"interval":{"type":"auto","scaling":1}}}],"series":[{"config":{"name":""},"function":"avg(anomaly_confidence)"}],"sort":[],"visualization":"line","visualization_config":{"interpolation":"linear","axis_type":"linear"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND anomaly_detector_name AND anomaly_confidence)"},"streams":[]},{"id":"f73a902f-a154-4b2d-8a11-e6b98a391a9f","type":"aggregation","config":{"column_pivots":[],"rollup":true,"row_pivots":[{"fields":["user_name"],"type":"values","config":{"limit":0}}],"series":[{"config":{"name":"Average anomaly_grade"},"function":"avg(anomaly_grade)"}],"sort":[],"visualization":"bar","visualization_config":{"barmode":"group","axis_type":"linear"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(user_name AND anomaly_grade)"},"streams":[]},{"id":"4b6e4eac-539c-4eff-9d44-40b61e079a2f","type":"aggregation","config":{"column_pivots":[{"fields":["anomaly_detector_name"],"type":"values","config":{"limit":0}}],"rollup":false,"row_pivots":[{"fields":["timestamp"],"type":"time","config":{"interval":{"type":"auto","scaling":1}}}],"series":[{"config":{"name":""},"function":"count()"}],"sort":[],"visualization":"bar","visualization_config":{"barmode":"stack","axis_type":"linear"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND anomaly_detector_name)"},"streams":[]},{"id":"59a1729d-2fe3-4687-a3b8-5c81d84a9bb1","type":"aggregation","config":{"column_pivots":[],"rollup":true,"row_pivots":[],"series":[{"config":{"name":null},"function":"card(user_name)"}],"sort":[],"visualization":"numeric","visualization_config":{"trend":true,"trend_preference":"LOWER"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND user_name) AND event_source_product:graylog_anomaly AND _exists_:(user_name)"},"streams":[]},{"id":"221246ac-a8ec-46a1-840d-769f25d73a3b","type":"aggregation","config":{"column_pivots":[],"rollup":true,"row_pivots":[{"fields":["anomaly_detector_name"],"type":"values","config":{"limit":0}}],"series":[{"config":{"name":"Average anomaly_grade"},"function":"avg(anomaly_grade)"}],"sort":[],"visualization":"bar","visualization_config":{"barmode":"group","axis_type":"linear"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(anomaly_detector_name AND anomaly_grade)"},"streams":[]},{"id":"fd47d65f-5c84-4aca-b2a2-70877dbf84e9","type":"aggregation","config":{"column_pivots":[],"rollup":true,"row_pivots":[],"series":[{"config":{"name":null},"function":"count()"}],"sort":[],"visualization":"numeric","visualization_config":{"trend":true,"trend_preference":"LOWER"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly"},"streams":[]},{"id":"c85c1315-69ff-4467-8b87-97aa238b1fcf","type":"aggregation","config":{"column_pivots":[],"formatting_settings":{"chart_colors":[{"field_name":"count()","chart_color":"#4c575d"}]},"rollup":true,"row_pivots":[{"fields":["timestamp"],"type":"time","config":{"interval":{"type":"auto","scaling":1}}}],"series":[{"config":{"name":null},"function":"count()"}],"sort":[],"visualization":"area","visualization_config":{"interpolation":"linear","axis_type":"linear"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":" _exists_:(event_source_product AND timestamp) AND event_source_product:graylog_anomaly"},"streams":[]},{"id":"71069faa-433b-4d2a-b908-5f5585a1e837","type":"aggregation","config":{"column_pivots":[{"fields":["user_name"],"type":"values","config":{"limit":0}}],"rollup":false,"row_pivots":[{"fields":["timestamp"],"type":"time","config":{"interval":{"type":"auto","scaling":1}}}],"series":[{"config":{"name":""},"function":"count()"}],"sort":[],"visualization":"bar","visualization_config":{"barmode":"stack","axis_type":"linear"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND user_name)"},"streams":[]},{"id":"aa1c8d2f-e385-40eb-94de-a7eed9c07984","type":"aggregation","config":{"column_pivots":[],"rollup":true,"row_pivots":[],"series":[{"config":{"name":null},"function":"card(anomaly_detector_name)"}],"sort":[],"visualization":"numeric","visualization_config":{"trend":true,"trend_preference":"LOWER"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_detector_name) AND event_source_product:graylog_anomaly"},"streams":[]},{"id":"81fc0ad4-3cdb-4245-b6fd-e28df25091e7","type":"aggregation","config":{"column_pivots":[],"rollup":true,"row_pivots":[],"series":[{"config":{"name":null},"function":"count()"}],"sort":[],"visualization":"numeric","visualization_config":{"trend":true,"trend_preference":"LOWER"},"event_annotation":false},"filters":[],"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_grade) AND event_source_product:graylog_anomaly AND anomaly_grade:[0.7 TO 1.0]"},"streams":[]}],"widget_mapping":{"81fc0ad4-3cdb-4245-b6fd-e28df25091e7":["1328c9b4-73fd-43d4-a64c-3c82706c7d90","eb43d78b-e874-494c-9299-4aff97bffc13"],"f73a902f-a154-4b2d-8a11-e6b98a391a9f":["1fa3fbfe-0d41-42d1-86b1-d666cdcd6273"],"59a1729d-2fe3-4687-a3b8-5c81d84a9bb1":["1a43c579-b833-425c-aed4-fc68b7bbb4c5","d79aaf59-307c-458f-81ac-1b70ceeb20c7"],"221246ac-a8ec-46a1-840d-769f25d73a3b":["12aad469-7450-4615-becb-f8b85734c77b"],"71069faa-433b-4d2a-b908-5f5585a1e837":["773fee94-65f4-49d4-9fc3-43c26f51eee7"],"4b6e4eac-539c-4eff-9d44-40b61e079a2f":["21f587b5-01dc-41e4-8e2a-7e8b81c3cc29"],"aa1c8d2f-e385-40eb-94de-a7eed9c07984":["b25e0d1f-2784-4adc-ade9-63ad9d4ad227","fed6c1cd-f163-4477-8d90-197fb9e335a9"],"10494c16-95dd-4613-adc3-9bc0ba9a5c26":["0f79f847-f210-4333-86c2-71e58ee8230d"],"fd47d65f-5c84-4aca-b2a2-70877dbf84e9":["12b9aec3-574d-445a-9048-13c66cdbd4fd","f2bd8935-d87d-4bfe-a342-a938c55f37db"],"c85c1315-69ff-4467-8b87-97aa238b1fcf":["d78463c2-70c3-449d-bc54-9f9c751b8541"]},"positions":{"81fc0ad4-3cdb-4245-b6fd-e28df25091e7":{"col":4,"row":19,"height":3,"width":3},"f73a902f-a154-4b2d-8a11-e6b98a391a9f":{"col":7,"row":30,"height":4,"width":6},"59a1729d-2fe3-4687-a3b8-5c81d84a9bb1":{"col":7,"row":19,"height":3,"width":3},"221246ac-a8ec-46a1-840d-769f25d73a3b":{"col":1,"row":30,"height":4,"width":6},"71069faa-433b-4d2a-b908-5f5585a1e837":{"col":7,"row":26,"height":4,"width":6},"4b6e4eac-539c-4eff-9d44-40b61e079a2f":{"col":1,"row":26,"height":4,"width":6},"aa1c8d2f-e385-40eb-94de-a7eed9c07984":{"col":10,"row":19,"height":3,"width":3},"10494c16-95dd-4613-adc3-9bc0ba9a5c26":{"col":7,"row":22,"height":4,"width":6},"fd47d65f-5c84-4aca-b2a2-70877dbf84e9":{"col":1,"row":19,"height":3,"width":3},"c85c1315-69ff-4467-8b87-97aa238b1fcf":{"col":1,"row":22,"height":4,"width":6}}}},"created_at":"2021-03-15T20:32:50.170Z","owner":"john.hartley"}'),f=JSON.parse('{"id":"656510c70548c8792779eea6","queries":[{"id":"ec57fdf4-03b8-4bd6-b436-623c0cfc6111","query":{"type":"elasticsearch","query_string":""},"timerange":{"from":300,"type":"relative"},"filter":null,"filters":[],"search_types":[{"timerange":{"source":"search_type","id":"fed6c1cd-f163-4477-8d90-197fb9e335a9","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_detector_name) AND event_source_product:graylog_anomaly"},"streams":[],"id":"b25e0d1f-2784-4adc-ade9-63ad9d4ad227","name":"trend","series":[{"type":"card","id":"card(anomaly_detector_name)","field":"anomaly_detector_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND anomaly_detector_name)"},"streams":[],"id":"21f587b5-01dc-41e4-8e2a-7e8b81c3cc29","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":false,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[{"type":"values","fields":["anomaly_detector_name"],"limit":15,"skip_empty_values":false}],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(anomaly_detector_name AND anomaly_grade)"},"streams":[],"id":"12aad469-7450-4615-becb-f8b85734c77b","name":"chart","series":[{"type":"avg","id":"Average anomaly_grade","field":"anomaly_grade"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[{"type":"values","fields":["anomaly_detector_name"],"limit":15,"skip_empty_values":false}],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"source":"search_type","id":"12b9aec3-574d-445a-9048-13c66cdbd4fd","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly"},"streams":[],"id":"f2bd8935-d87d-4bfe-a342-a938c55f37db","name":"trend","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND user_name) AND event_source_product:graylog_anomaly AND _exists_:(user_name)"},"streams":[],"id":"d79aaf59-307c-458f-81ac-1b70ceeb20c7","name":"chart","series":[{"type":"card","id":"card(user_name)","field":"user_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND user_name)"},"streams":[],"id":"773fee94-65f4-49d4-9fc3-43c26f51eee7","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":false,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[{"type":"values","fields":["user_name"],"limit":15,"skip_empty_values":false}],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_detector_name) AND event_source_product:graylog_anomaly"},"streams":[],"id":"fed6c1cd-f163-4477-8d90-197fb9e335a9","name":"chart","series":[{"type":"card","id":"card(anomaly_detector_name)","field":"anomaly_detector_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(user_name AND anomaly_grade)"},"streams":[],"id":"1fa3fbfe-0d41-42d1-86b1-d666cdcd6273","name":"chart","series":[{"type":"avg","id":"Average anomaly_grade","field":"anomaly_grade"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[{"type":"values","fields":["user_name"],"limit":15,"skip_empty_values":false}],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"source":"search_type","id":"d79aaf59-307c-458f-81ac-1b70ceeb20c7","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND user_name) AND event_source_product:graylog_anomaly AND _exists_:(user_name)"},"streams":[],"id":"1a43c579-b833-425c-aed4-fc68b7bbb4c5","name":"trend","series":[{"type":"card","id":"card(user_name)","field":"user_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":" _exists_:(event_source_product AND timestamp) AND event_source_product:graylog_anomaly"},"streams":[],"id":"d78463c2-70c3-449d-bc54-9f9c751b8541","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_grade) AND event_source_product:graylog_anomaly AND anomaly_grade:[0.7 TO 1.0]"},"streams":[],"id":"1328c9b4-73fd-43d4-a64c-3c82706c7d90","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"source":"search_type","id":"1328c9b4-73fd-43d4-a64c-3c82706c7d90","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_grade) AND event_source_product:graylog_anomaly AND anomaly_grade:[0.7 TO 1.0]"},"streams":[],"id":"eb43d78b-e874-494c-9299-4aff97bffc13","name":"trend","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly"},"streams":[],"id":"12b9aec3-574d-445a-9048-13c66cdbd4fd","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND anomaly_detector_name AND anomaly_confidence)"},"streams":[],"id":"0f79f847-f210-4333-86c2-71e58ee8230d","name":"chart","series":[{"type":"avg","id":"avg(anomaly_confidence)","field":"anomaly_confidence"}],"sort":[],"rollup":false,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[{"type":"values","fields":["anomaly_detector_name"],"limit":15,"skip_empty_values":false}],"filter":null,"filters":[]}]}],"parameters":[]}'),y=JSON.parse('{"execution":{"done":true,"cancelled":false,"completed_exceptionally":false},"results":{"ec57fdf4-03b8-4bd6-b436-623c0cfc6111":{"query":{"id":"ec57fdf4-03b8-4bd6-b436-623c0cfc6111","timerange":{"from":300,"type":"relative"},"filter":{"type":"or","filters":[{"type":"stream","id":"653972ed4062770d2af9d2c9"},{"type":"stream","id":"000000000000000000000001"},{"type":"stream","id":"653972eb4062770d2af9d298"},{"type":"stream","id":"653972ec4062770d2af9d2b7"},{"type":"stream","id":"653972fe4062770d2af9d36f"},{"type":"stream","id":"653972ec4062770d2af9d2ae"},{"type":"stream","id":"653980454062770d2af9fd86"},{"type":"stream","id":"655634e28cca23167c7dfdce"},{"type":"stream","id":"653972ec4062770d2af9d2a5"},{"type":"stream","id":"653972ed4062770d2af9d2c0"}]},"filters":[],"query":{"type":"elasticsearch","query_string":""},"search_types":[{"timerange":{"source":"search_type","id":"fed6c1cd-f163-4477-8d90-197fb9e335a9","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_detector_name) AND event_source_product:graylog_anomaly"},"streams":[],"id":"b25e0d1f-2784-4adc-ade9-63ad9d4ad227","name":"trend","series":[{"type":"card","id":"card(anomaly_detector_name)","field":"anomaly_detector_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND anomaly_detector_name)"},"streams":[],"id":"21f587b5-01dc-41e4-8e2a-7e8b81c3cc29","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":false,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[{"type":"values","fields":["anomaly_detector_name"],"limit":15,"skip_empty_values":false}],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(anomaly_detector_name AND anomaly_grade)"},"streams":[],"id":"12aad469-7450-4615-becb-f8b85734c77b","name":"chart","series":[{"type":"avg","id":"Average anomaly_grade","field":"anomaly_grade"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[{"type":"values","fields":["anomaly_detector_name"],"limit":15,"skip_empty_values":false}],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"source":"search_type","id":"12b9aec3-574d-445a-9048-13c66cdbd4fd","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly"},"streams":[],"id":"f2bd8935-d87d-4bfe-a342-a938c55f37db","name":"trend","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND user_name) AND event_source_product:graylog_anomaly AND _exists_:(user_name)"},"streams":[],"id":"d79aaf59-307c-458f-81ac-1b70ceeb20c7","name":"chart","series":[{"type":"card","id":"card(user_name)","field":"user_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND user_name)"},"streams":[],"id":"773fee94-65f4-49d4-9fc3-43c26f51eee7","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":false,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[{"type":"values","fields":["user_name"],"limit":15,"skip_empty_values":false}],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_detector_name) AND event_source_product:graylog_anomaly"},"streams":[],"id":"fed6c1cd-f163-4477-8d90-197fb9e335a9","name":"chart","series":[{"type":"card","id":"card(anomaly_detector_name)","field":"anomaly_detector_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(user_name AND anomaly_grade)"},"streams":[],"id":"1fa3fbfe-0d41-42d1-86b1-d666cdcd6273","name":"chart","series":[{"type":"avg","id":"Average anomaly_grade","field":"anomaly_grade"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[{"type":"values","fields":["user_name"],"limit":15,"skip_empty_values":false}],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"source":"search_type","id":"d79aaf59-307c-458f-81ac-1b70ceeb20c7","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND user_name) AND event_source_product:graylog_anomaly AND _exists_:(user_name)"},"streams":[],"id":"1a43c579-b833-425c-aed4-fc68b7bbb4c5","name":"trend","series":[{"type":"card","id":"card(user_name)","field":"user_name"}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":" _exists_:(event_source_product AND timestamp) AND event_source_product:graylog_anomaly"},"streams":[],"id":"d78463c2-70c3-449d-bc54-9f9c751b8541","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_grade) AND event_source_product:graylog_anomaly AND anomaly_grade:[0.7 TO 1.0]"},"streams":[],"id":"1328c9b4-73fd-43d4-a64c-3c82706c7d90","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"source":"search_type","id":"1328c9b4-73fd-43d4-a64c-3c82706c7d90","offset":"1i","type":"offset"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product AND anomaly_grade) AND event_source_product:graylog_anomaly AND anomaly_grade:[0.7 TO 1.0]"},"streams":[],"id":"eb43d78b-e874-494c-9299-4aff97bffc13","name":"trend","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly"},"streams":[],"id":"12b9aec3-574d-445a-9048-13c66cdbd4fd","name":"chart","series":[{"type":"count","id":"count()","field":null}],"sort":[],"rollup":true,"type":"pivot","row_groups":[],"column_groups":[],"filter":null,"filters":[]},{"timerange":{"from":86400,"type":"relative"},"query":{"type":"elasticsearch","query_string":"_exists_:(event_source_product) AND event_source_product:graylog_anomaly AND _exists_:(timestamp AND anomaly_detector_name AND anomaly_confidence)"},"streams":[],"id":"0f79f847-f210-4333-86c2-71e58ee8230d","name":"chart","series":[{"type":"avg","id":"avg(anomaly_confidence)","field":"anomaly_confidence"}],"sort":[],"rollup":false,"type":"pivot","row_groups":[{"type":"time","fields":["timestamp"],"interval":{"type":"auto","scaling":1}}],"column_groups":[{"type":"values","fields":["anomaly_detector_name"],"limit":15,"skip_empty_values":false}],"filter":null,"filters":[]}]},"execution_stats":{"duration":1102,"timestamp":"2023-11-30T14:51:55.065Z","effective_timerange":{"from":"2023-11-30T14:46:56.168Z","to":"2023-11-30T14:51:56.168Z","type":"absolute"}},"search_types":{"773fee94-65f4-49d4-9fc3-43c26f51eee7":{"name":"chart","id":"773fee94-65f4-49d4-9fc3-43c26f51eee7","rows":[{"key":["2023-11-29T18:00:00.000Z"],"values":[{"key":["kpearson-dkstp$","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T18:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T19:00:00.000Z"],"values":[{"key":["abritt","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:30:00.000Z"],"values":[{"key":["abritt","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:00:00.000Z"],"values":[{"key":["abritt","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:30:00.000Z"],"values":[{"key":["dbenitez-dkstp$","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["tlott","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:00:00.000Z"],"values":[{"key":["dmiranda-dkstp$","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T22:00:00.000Z"],"values":[{"key":["tfarley-dkstp$","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T22:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T23:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T23:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T00:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T00:30:00.000Z"],"values":[{"key":["cmcknight-dkstp$","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T01:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T01:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T02:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T02:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T03:00:00.000Z"],"values":[{"key":["lbusby","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T03:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T04:00:00.000Z"],"values":[{"key":["lbusby","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T04:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T05:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T05:30:00.000Z"],"values":[{"key":["kpearson-dkstp$","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T06:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T06:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T07:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T07:30:00.000Z"],"values":[{"key":["tfarley","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T08:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T08:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T09:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T09:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T10:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T10:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T11:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T11:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T12:00:00.000Z"],"values":[{"key":["lbusby","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T12:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T13:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T13:30:00.000Z"],"values":[{"key":["tfarley","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T14:00:00.000Z"],"values":[{"key":["mgray","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"}],"total":16,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"d79aaf59-307c-458f-81ac-1b70ceeb20c7":{"name":"chart","id":"d79aaf59-307c-458f-81ac-1b70ceeb20c7","rows":[{"key":[],"values":[{"key":["card(user_name)"],"value":10,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":16,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"1fa3fbfe-0d41-42d1-86b1-d666cdcd6273":{"name":"chart","id":"1fa3fbfe-0d41-42d1-86b1-d666cdcd6273","rows":[{"key":["abritt"],"values":[{"key":["Average anomaly_grade"],"value":0.11666666716337204,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["lbusby"],"values":[{"key":["Average anomaly_grade"],"value":0.14333333323399225,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["kpearson-dkstp$"],"values":[{"key":["Average anomaly_grade"],"value":0.1599999964237213,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["tfarley"],"values":[{"key":["Average anomaly_grade"],"value":0.11999999731779099,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["cmcknight-dkstp$"],"values":[{"key":["Average anomaly_grade"],"value":0.1599999964237213,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["dbenitez-dkstp$"],"values":[{"key":["Average anomaly_grade"],"value":0.019999999552965164,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["dmiranda-dkstp$"],"values":[{"key":["Average anomaly_grade"],"value":0.12999999523162842,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["mgray"],"values":[{"key":["Average anomaly_grade"],"value":0.15000000596046448,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["tfarley-dkstp$"],"values":[{"key":["Average anomaly_grade"],"value":0.09000000357627869,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["tlott"],"values":[{"key":["Average anomaly_grade"],"value":0.07999999821186066,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":[],"values":[{"key":["Average anomaly_grade"],"value":0.12312499922700226,"rollup":true,"source":"row-inner"}],"source":"non-leaf"}],"total":16,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"eb43d78b-e874-494c-9299-4aff97bffc13":{"name":"trend","id":"eb43d78b-e874-494c-9299-4aff97bffc13","rows":[{"key":[],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":0,"type":"pivot","effective_timerange":{"from":"2023-11-28T14:51:56.167Z","to":"2023-11-29T14:51:56.167Z","type":"absolute"}},"0f79f847-f210-4333-86c2-71e58ee8230d":{"name":"chart","id":"0f79f847-f210-4333-86c2-71e58ee8230d","rows":[{"key":["2023-11-29T15:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.8250000178813934,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T16:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T16:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T17:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.8199999928474426,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T17:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T18:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.75,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.550000011920929,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T18:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.5899999737739563,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.6200000047683716,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.6600000262260437,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.5099999904632568,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.7200000286102295,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.6800000071525574,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.6650000214576721,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.8899999856948853,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.7400000095367432,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T22:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.5699999928474426,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T22:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.6200000047683716,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T23:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T23:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T00:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.550000011920929,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T00:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.699999988079071,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T01:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T01:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T02:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T02:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T03:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.699999988079071,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T03:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T04:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.6200000047683716,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.9399999976158142,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T04:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T05:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T05:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.5299999713897705,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.6000000238418579,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T06:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T06:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T07:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T07:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.7099999785423279,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T08:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T08:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T09:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T09:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T10:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T10:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T11:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T11:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T12:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.8399999737739563,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T12:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.8700000047683716,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T13:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T13:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.9300000071525574,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T14:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","avg(anomaly_confidence)"],"value":0.9700000286102295,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","avg(anomaly_confidence)"],"value":0.8100000023841858,"rollup":false,"source":"col-leaf"}],"source":"leaf"}],"total":32,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"1328c9b4-73fd-43d4-a64c-3c82706c7d90":{"name":"chart","id":"1328c9b4-73fd-43d4-a64c-3c82706c7d90","rows":[{"key":[],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":0,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"12aad469-7450-4615-becb-f8b85734c77b":{"name":"chart","id":"12aad469-7450-4615-becb-f8b85734c77b","rows":[{"key":["Cisco ASA - Unusual Data Transfer"],"values":[{"key":["Average anomaly_grade"],"value":0.1112500000745058,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["Windows Security Event Log - Failed Authentication"],"values":[{"key":["Average anomaly_grade"],"value":0.12312499922700226,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":[],"values":[{"key":["Average anomaly_grade"],"value":0.11718749965075403,"rollup":true,"source":"row-inner"}],"source":"non-leaf"}],"total":32,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"21f587b5-01dc-41e4-8e2a-7e8b81c3cc29":{"name":"chart","id":"21f587b5-01dc-41e4-8e2a-7e8b81c3cc29","rows":[{"key":["2023-11-29T15:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":2,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T16:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T16:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T17:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":2,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T17:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T18:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":2,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T18:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":2,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T22:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T22:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-29T23:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-29T23:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T00:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T00:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T01:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T01:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T02:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T02:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T03:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T03:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T04:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T04:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T05:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T05:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T06:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T06:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T07:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T07:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T08:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T08:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T09:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T09:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T10:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T10:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T11:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T11:30:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T12:00:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T12:30:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T13:00:00.000Z"],"values":[],"source":"leaf"},{"key":["2023-11-30T13:30:00.000Z"],"values":[{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"},{"key":["2023-11-30T14:00:00.000Z"],"values":[{"key":["Cisco ASA - Unusual Data Transfer","count()"],"value":1,"rollup":false,"source":"col-leaf"},{"key":["Windows Security Event Log - Failed Authentication","count()"],"value":1,"rollup":false,"source":"col-leaf"}],"source":"leaf"}],"total":32,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"12b9aec3-574d-445a-9048-13c66cdbd4fd":{"name":"chart","id":"12b9aec3-574d-445a-9048-13c66cdbd4fd","rows":[{"key":[],"values":[{"key":["count()"],"value":32,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":32,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"1a43c579-b833-425c-aed4-fc68b7bbb4c5":{"name":"trend","id":"1a43c579-b833-425c-aed4-fc68b7bbb4c5","rows":[{"key":[],"values":[{"key":["card(user_name)"],"value":12,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":22,"type":"pivot","effective_timerange":{"from":"2023-11-28T14:51:56.167Z","to":"2023-11-29T14:51:56.167Z","type":"absolute"}},"b25e0d1f-2784-4adc-ade9-63ad9d4ad227":{"name":"trend","id":"b25e0d1f-2784-4adc-ade9-63ad9d4ad227","rows":[{"key":[],"values":[{"key":["card(anomaly_detector_name)"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":42,"type":"pivot","effective_timerange":{"from":"2023-11-28T14:51:56.167Z","to":"2023-11-29T14:51:56.167Z","type":"absolute"}},"fed6c1cd-f163-4477-8d90-197fb9e335a9":{"name":"chart","id":"fed6c1cd-f163-4477-8d90-197fb9e335a9","rows":[{"key":[],"values":[{"key":["card(anomaly_detector_name)"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":32,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"d78463c2-70c3-449d-bc54-9f9c751b8541":{"name":"chart","id":"d78463c2-70c3-449d-bc54-9f9c751b8541","rows":[{"key":["2023-11-29T15:30:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T16:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T16:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T17:00:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T17:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T18:00:00.000Z"],"values":[{"key":["count()"],"value":3,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T18:30:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:00:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T19:30:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:00:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T20:30:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:00:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T21:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T22:00:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T22:30:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T23:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-29T23:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T00:00:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T00:30:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T01:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T01:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T02:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T02:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T03:00:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T03:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T04:00:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T04:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T05:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T05:30:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T06:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T06:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T07:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T07:30:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T08:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T08:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T09:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T09:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T10:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T10:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T11:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T11:30:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T12:00:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T12:30:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T13:00:00.000Z"],"values":[{"key":["count()"],"value":0,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T13:30:00.000Z"],"values":[{"key":["count()"],"value":1,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":["2023-11-30T14:00:00.000Z"],"values":[{"key":["count()"],"value":2,"rollup":true,"source":"row-leaf"}],"source":"leaf"},{"key":[],"values":[{"key":["count()"],"value":32,"rollup":true,"source":"row-inner"}],"source":"non-leaf"}],"total":32,"type":"pivot","effective_timerange":{"from":"2023-11-29T14:51:56.167Z","to":"2023-11-30T14:51:56.167Z","type":"absolute"}},"f2bd8935-d87d-4bfe-a342-a938c55f37db":{"name":"trend","id":"f2bd8935-d87d-4bfe-a342-a938c55f37db","rows":[{"key":[],"values":[{"key":["count()"],"value":42,"rollup":true,"source":"row-leaf"}],"source":"leaf"}],"total":42,"type":"pivot","effective_timerange":{"from":"2023-11-28T14:51:56.167Z","to":"2023-11-29T14:51:56.167Z","type":"absolute"}}},"errors":[],"state":"COMPLETED"}},"id":"6568a18b0548c879277c0d9d","owner":"admin","search_id":"656510c70548c8792779eea6"}'),d=[{positionX:"50%",positionY:"110px",description:"Get a summary of the anomalies that are running, how many have been detected, and how that compares to the previous time period."},{positionX:"60%",positionY:"550px",description:"Confidence intervals tell you how far off the normal the behavior is."},{positionX:"40%",positionY:"910px",description:"There are detectors for different types of anomalies \u2013 quickly see which ones are generating alerts."},{positionX:"70%",positionY:"910px",description:"Identify user accounts that have unusual-for-them behaviors for logons or security events."}],m=()=>a.createElement(r.Qc,{title:"Anomalies"},a.createElement(_.A,{viewJson:u,searchJson:f,searchJobResult:y,hotspots:d}))},q5MWReSo:(g,i,e)=>{e.d(i,{A:()=>O});var a=e("Z7aTuO5B"),r=e("J6y4/h8P"),_=e("r0DwUTl9"),u=e("6j4Sgo2g");const f=80,y=(0,r.keyframes)`
0% {
transform: scale(.5);
opacity: 1;
}
100% {
transform: scale(1.5);
opacity: 0;
}
`,d=r.default.button(({theme:o})=>(0,r.css)`
&& {
border-radius: 50%;
height: ${f}px;
width: ${f}px;
background: ${o.colors.variant.warning};
color: ${o.utils.contrastingColor(o.colors.variant.warning)};
border: 0;
font-size: ${o.fonts.size.huge};
&:hover {
background: ${o.colors.variant.warning};
color: ${o.utils.contrastingColor(o.colors.variant.warning)};
}
}
&::before {
background: ${o.colors.variant.warning};
content: "";
width: 100%;
height: 100%;
position: absolute;
z-index: -1;
opacity: 0;
animation: ${y} 2s infinite;
border-radius: 50%;
left: 0;
top: 0;
}
`),p=r.default.div(({$positionX:o,$positionY:l})=>(0,r.css)`
position: absolute;
top: ${l};
left: calc(${o} - ${f/2}px);
`),T=({children:o,positionX:l,positionY:c,index:t})=>{const[s,n]=(0,a.useState)(!1),v=(0,a.useRef)(),F=(0,a.useRef)(),k=()=>n(!0),b=()=>n(!1);return a.createElement(p,{$positionX:l,$positionY:c,ref:F},a.createElement(u.A,{opened:s,position:"bottom",id:"session-badge-details",width:275},a.createElement(u.A.Target,null,a.createElement(d,{onMouseOver:k,onMouseOut:b,onFocus:k,onBlur:b,ref:v},t+1)),a.createElement(u.A.Dropdown,null,o)))};var A=e("DjctQb+S"),h=e("0eB11aFj"),Z=e("wi0Y4c9s"),w=e("Qv8wg03E"),D=e("MDn/VShH"),N=e("/coHI+Jz"),S=e("UmnljV2q"),x=e("53I4yQGE"),E=e("AMSn1A3N");const q=E.A.empty(),C=({searchJson:o,viewJson:l,searchJobResult:c})=>{const t=(0,a.useMemo)(()=>{const v=N.A.fromJSON(o);return S.A.fromJSON(l).toBuilder().search(v).build()},[o,l]),s=(0,a.useMemo)(()=>({result:new x.A(c),widgetMapping:t.widgetMapping}),[c,t.widgetMapping]),n=(0,a.useMemo)(()=>({execute:async()=>s,parse:async()=>q,resultMapper:v=>v}),[s]);return a.createElement(w.A.Provider,{value:n},a.createElement(D.A,{view:Promise.resolve(t),isNew:!1,searchResult:s}))},L=(0,r.default)(h.A)`
.page-content-grid {
position: relative;
}
`,W=r.default.div`
position: absolute;
top: 0;
left: 0;
right: 0;
height: 100%;
background: transparent;
z-index: 1;
`,U=o=>({children:l})=>a.createElement(L,null,a.createElement(W,null,o.map(({description:c,positionX:t,positionY:s},n)=>a.createElement(T,{positionX:t,positionY:s,index:n,key:`hotspot-${n}`},c))),a.createElement("div",{inert:""},l)),O=({searchJson:o,viewJson:l,searchJobResult:c,hotspots:t})=>{const s=(0,a.useMemo)(()=>({sidebar:{isShown:!1},viewActions:A.GI,searchAreaContainer:{component:U(t)}}),[t]);return a.createElement(Z.A,{value:s},a.createElement(C,{searchJson:o,viewJson:l,searchJobResult:c}))}},wi0Y4c9s:(g,i,e)=>{e.d(i,{A:()=>y});var a=e("Z7aTuO5B"),r=e("wXrUUKFq"),_=e.n(r),u=e("DjctQb+S");const y=({children:d,value:p})=>{const m=(0,a.useMemo)(()=>_()({},u.Ke,p),[p]);return a.createElement(u.Ay.Provider,{value:m},d)}}}]);})();
//# sourceMappingURL=bb8c8232-4868.34a48bf661e1144ff850.js.map
© 2015 - 2024 Weber Informatics LLC | Privacy Policy