Data hosted with ♥ by Pastebin.com - Download Raw - See Original
  1. <form>
  2.   <label>ElJefe_OverSight</label>
  3.   <fieldset submitButton="false" autoRun="false">
  4.     <input type="time" token="field1" searchWhenChanged="true">
  5.       <label/>
  6.       <default>
  7.         <earliestTime>@d</earliestTime>
  8.         <latestTime>now</latestTime>
  9.       </default>
  10.     </input>
  11.     <input type="text" token="hostname" searchWhenChanged="true">
  12.       <label>Hostname</label>
  13.       <default>*</default>
  14.     </input>
  15.   </fieldset>
  16.   <row>
  17.     <panel>
  18.       <chart>
  19.         <title>Number of Events</title>
  20.         <searchString>sourcetype="eljefe" station=$hostname$  | stats count by station | sort -count</searchString>
  21.         <earliestTime>$field1.earliest$</earliestTime>
  22.         <latestTime>$field1.latest$</latestTime>
  23.         <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
  24.         <option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
  25.         <option name="charting.axisTitleX.visibility">visible</option>
  26.         <option name="charting.axisTitleY.visibility">visible</option>
  27.         <option name="charting.axisTitleY2.visibility">visible</option>
  28.         <option name="charting.axisX.scale">linear</option>
  29.         <option name="charting.axisY.scale">linear</option>
  30.         <option name="charting.axisY2.enabled">false</option>
  31.         <option name="charting.axisY2.scale">linear</option>
  32.         <option name="charting.chart">column</option>
  33.         <option name="charting.chart.nullValueMode">gaps</option>
  34.         <option name="charting.chart.sliceCollapsingThreshold">0.01</option>
  35.         <option name="charting.chart.stackMode">default</option>
  36.         <option name="charting.chart.style">shiny</option>
  37.         <option name="charting.drilldown">all</option>
  38.         <option name="charting.layout.splitSeries">0</option>
  39.         <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
  40.         <option name="charting.legend.placement">bottom</option>
  41.         <option name="wrap">true</option>
  42.         <option name="rowNumbers">false</option>
  43.         <option name="dataOverlayMode">none</option>
  44.         <option name="count">10</option>
  45.       </chart>
  46.     </panel>
  47.     <panel>
  48.       <chart>
  49.         <title>Binaries by time</title>
  50.         <searchString>sourcetype=eljefe | timechart count(parent_binary) as processes by station</searchString>
  51.         <earliestTime>$field1.earliest$</earliestTime>
  52.         <latestTime>$field1.latest$</latestTime>
  53.         <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
  54.         <option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
  55.         <option name="charting.axisTitleX.visibility">visible</option>
  56.         <option name="charting.axisTitleY.visibility">visible</option>
  57.         <option name="charting.axisTitleY2.visibility">visible</option>
  58.         <option name="charting.axisX.scale">linear</option>
  59.         <option name="charting.axisY.scale">linear</option>
  60.         <option name="charting.axisY2.enabled">false</option>
  61.         <option name="charting.axisY2.scale">inherit</option>
  62.         <option name="charting.chart">line</option>
  63.         <option name="charting.chart.nullValueMode">gaps</option>
  64.         <option name="charting.chart.sliceCollapsingThreshold">0.01</option>
  65.         <option name="charting.chart.stackMode">default</option>
  66.         <option name="charting.chart.style">shiny</option>
  67.         <option name="charting.drilldown">all</option>
  68.         <option name="charting.layout.splitSeries">0</option>
  69.         <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
  70.         <option name="charting.legend.placement">right</option>
  71.       </chart>
  72.     </panel>
  73.   </row>
  74.   <row>
  75.     <panel>
  76.       <table>
  77.         <title>Unique Binaries</title>
  78.         <searchString>sourcetype="eljefe" $hostname$|table station child_binary parent_binary user privileges parent_hash_sha256 |dedup parent_hash_sha256</searchString>
  79.         <earliestTime>$field1.earliest$</earliestTime>
  80.         <latestTime>$field1.latest$</latestTime>
  81.         <option name="wrap">true</option>
  82.         <option name="rowNumbers">false</option>
  83.         <option name="dataOverlayMode">none</option>
  84.         <option name="drilldown">cell</option>
  85.         <option name="count">10</option>
  86.       </table>
  87.     </panel>
  88.     <panel>
  89.       <table>
  90.         <title>Rare Children Overview</title>
  91.         <searchString>sourcetype=eljefe | transaction parent_pid parent_binary child_binary station| rare child_binary by station limit=3</searchString>
  92.         <earliestTime>$field1.earliest$</earliestTime>
  93.         <latestTime>$field1.latest$</latestTime>
  94.         <option name="wrap">true</option>
  95.         <option name="rowNumbers">false</option>
  96.         <option name="dataOverlayMode">none</option>
  97.         <option name="drilldown">cell</option>
  98.         <option name="count">10</option>
  99.       </table>
  100.     </panel>
  101.   </row>
  102.   <row>
  103.     <panel>
  104.       <table>
  105.         <title>Processes executed from temp</title>
  106.         <searchString>sourcetype=eljefe parent_binary=*temp* child_binary!=*MpCmdRun.exe| table station parent_binary child_binary</searchString>
  107.         <earliestTime>$field1.earliest$</earliestTime>
  108.         <latestTime>$field1.latest$</latestTime>
  109.         <option name="wrap">true</option>
  110.         <option name="rowNumbers">false</option>
  111.         <option name="dataOverlayMode">none</option>
  112.         <option name="drilldown">cell</option>
  113.         <option name="count">10</option>
  114.       </table>
  115.     </panel>
  116.     <panel>
  117.       <table>
  118.         <title>Potentially Dangerous</title>
  119.         <searchString>sourcetype=eljefe parent_binary=*lsass.exe OR child_binary=*lsass.exe | table station parent_binary child_binary</searchString>
  120.         <earliestTime>$field1.earliest$</earliestTime>
  121.         <latestTime>$field1.latest$</latestTime>
  122.         <option name="wrap">true</option>
  123.         <option name="rowNumbers">false</option>
  124.         <option name="dataOverlayMode">none</option>
  125.         <option name="drilldown">cell</option>
  126.       </table>
  127.     </panel>
  128.   </row>
  129. </form>