Skip to content

Instantly share code, notes, and snippets.

@dancwilliams
Created April 26, 2015 14:29
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save dancwilliams/b78dbb3b87cc0455f666 to your computer and use it in GitHub Desktop.
Save dancwilliams/b78dbb3b87cc0455f666 to your computer and use it in GitHub Desktop.
Suricata-ALL
{
"index": {
"default": "NO_TIME_FILTER_OR_INDEX_PATTERN_NOT_MATCHED",
"pattern": "[logstash-]YYYY.MM.DD",
"warm_fields": true,
"interval": "day"
},
"style": "light",
"rows": [
{
"notice": false,
"collapsable": true,
"collapse": false,
"title": "Timeline",
"editable": true,
"height": "200px",
"panels": [
{
"show_query": true,
"bars": true,
"y-axis": true,
"zoomlinks": true,
"annotate": {
"sort": [
"_score",
"desc"
],
"query": "*",
"enable": false,
"size": 20,
"field": "_type"
},
"intervals": [
"auto",
"1s",
"1m",
"5m",
"10m",
"30m",
"1h",
"3h",
"12h",
"1d",
"1w",
"1M",
"1y"
],
"spyable": true,
"timezone": "browser",
"linewidth": 1,
"fill": 1,
"scale": 1,
"span": 12,
"title": "Events over time",
"tooltip": {
"value_type": "individual",
"query_as_alias": true
},
"legend": true,
"derivative": false,
"percentage": false,
"auto_int": true,
"type": "histogram",
"value_field": null,
"x-axis": true,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"zerofill": true,
"grid": {
"max": null,
"min": 0
},
"group": [
"default"
],
"stack": true,
"legend_counts": true,
"time_field": "@timestamp",
"interval": "30s",
"lines": false,
"y_format": "short",
"points": false,
"mode": "count",
"pointradius": 5,
"resolution": 200,
"options": true,
"interactive": true
}
]
},
{
"notice": false,
"panels": [
{
"exclude": [],
"map": "world",
"span": 6,
"title": "World",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"field": "geoip.country_code2",
"colors": [
"#A0E2E2",
"#265656"
],
"index_limit": 0,
"error": false,
"spyable": true,
"loadingEditor": false,
"type": "map",
"size": 200
},
{
"exclude": [],
"map": "europe",
"span": 3,
"title": "Europe",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"field": "geoip.country_code2",
"colors": [
"#A0E2E2",
"#265656"
],
"index_limit": 0,
"error": false,
"spyable": true,
"type": "map",
"size": 100
},
{
"exclude": [],
"map": "usa",
"span": 3,
"title": "USA",
"error": false,
"editable": true,
"field": "geoip.region_name.raw",
"colors": [
"#A0E2E2",
"#265656"
],
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"loadingEditor": false,
"type": "map",
"size": 100
}
],
"collapse": false,
"title": "Maps",
"editable": true,
"height": "250px",
"collapsable": true
},
{
"notice": false,
"panels": [
{
"ago": "2w",
"style": {
"font-size": "14pt"
},
"span": 2,
"reverse": false,
"title": "2 WEEK TREND",
"editable": true,
"arrangement": "vertical",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"loadingEditor": false,
"type": "trends"
},
{
"ago": "1w",
"style": {
"font-size": "14pt"
},
"span": 2,
"reverse": false,
"title": "1 Week Trend",
"editable": true,
"arrangement": "vertical",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"loadingEditor": false,
"type": "trends"
},
{
"ago": "2d",
"style": {
"font-size": "14pt"
},
"span": 2,
"reverse": false,
"title": "2 Day Trend",
"editable": true,
"arrangement": "vertical",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"type": "trends"
},
{
"ago": "1d",
"style": {
"font-size": "14pt"
},
"span": 2,
"reverse": false,
"title": "1 Day Trend",
"editable": true,
"arrangement": "vertical",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"type": "trends"
},
{
"ago": "4h",
"style": {
"font-size": "14pt"
},
"span": 2,
"reverse": false,
"title": "4 Hour Trend",
"editable": true,
"arrangement": "vertical",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"type": "trends"
},
{
"ago": "1h",
"style": {
"font-size": "14pt"
},
"span": 2,
"reverse": false,
"title": "1 hour trend",
"editable": true,
"arrangement": "vertical",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"loadingEditor": false,
"type": "trends"
}
],
"collapse": false,
"title": "Trends",
"editable": true,
"height": "200px",
"collapsable": true
},
{
"notice": false,
"panels": [
{
"labels": true,
"tmode": "terms",
"valuefield": "",
"exclude": [],
"spyable": true,
"size": 10,
"style": {
"font-size": "10pt"
},
"span": 3,
"title": "SSH Version",
"tilt": false,
"arrangement": "horizontal",
"field": "ssh.server.proto_version.raw",
"other": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "pie",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
},
{
"labels": true,
"tmode": "terms",
"valuefield": "",
"exclude": [],
"spyable": true,
"size": 10,
"style": {
"font-size": "10pt"
},
"span": 3,
"title": "DNS RRTYPE",
"tilt": false,
"arrangement": "horizontal",
"field": "dns.rrtype.raw",
"other": false,
"loadingEditor": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "bar",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
},
{
"labels": true,
"tmode": "terms",
"valuefield": "",
"exclude": [
""
],
"spyable": true,
"size": 10,
"style": {
"font-size": "10pt"
},
"span": 3,
"title": "File Types",
"tilt": false,
"arrangement": "horizontal",
"field": "fileinfo.type.raw",
"other": false,
"loadingEditor": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "table",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
},
{
"labels": true,
"tmode": "terms",
"valuefield": "",
"exclude": [],
"spyable": true,
"size": 10,
"style": {
"font-size": "10pt"
},
"span": 3,
"title": "TLS Version",
"tilt": false,
"arrangement": "horizontal",
"field": "tls.version.raw",
"other": false,
"loadingEditor": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "table",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
}
],
"collapse": false,
"title": "NSM",
"editable": true,
"height": "200px",
"collapsable": true
},
{
"notice": false,
"collapsable": true,
"collapse": false,
"title": "Global data",
"editable": true,
"height": "250px",
"panels": [
{
"labels": true,
"tmode": "terms",
"valuefield": "geoip.location",
"exclude": [],
"spyable": true,
"size": 10,
"style": {
"font-size": "10pt"
},
"span": 4,
"title": "All Events",
"tilt": false,
"arrangement": "horizontal",
"field": "event_type.raw",
"other": false,
"loadingEditor": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "pie",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
},
{
"labels": true,
"tmode": "terms",
"valuefield": "",
"exclude": [],
"spyable": true,
"size": 10,
"style": {
"font-size": "10pt"
},
"span": 4,
"title": "TCP/UDP",
"tilt": false,
"arrangement": "horizontal",
"field": "proto.raw",
"other": false,
"loadingEditor": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "pie",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
},
{
"labels": true,
"tmode": "terms",
"valuefield": "",
"exclude": [],
"spyable": true,
"size": 7,
"style": {
"font-size": "10pt"
},
"span": 4,
"title": "Top Alert Signatures",
"tilt": false,
"arrangement": "horizontal",
"field": "alert.signature.raw",
"other": false,
"loadingEditor": false,
"type": "terms",
"missing": false,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"chart": "table",
"counter_pos": "above",
"tstat": "total",
"donut": false,
"error": false,
"order": "count"
}
]
},
{
"notice": false,
"collapsable": true,
"collapse": false,
"title": "GeoIP Coordinates",
"editable": true,
"height": "550px",
"panels": [
{
"span": 12,
"title": "GeoIP Localization",
"error": false,
"editable": true,
"tooltip": "_id",
"field": "geoip.coordinates",
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"spyable": true,
"loadingEditor": false,
"type": "bettermap",
"size": 1000
}
]
},
{
"title": "TEST",
"height": "150px",
"editable": true,
"collapse": false,
"collapsable": true,
"panels": [
{
"error": false,
"span": 4,
"editable": true,
"type": "terms",
"loadingEditor": false,
"field": "geoip.city_name.raw",
"exclude": [],
"missing": false,
"other": false,
"size": 10,
"order": "count",
"style": {
"font-size": "10pt"
},
"donut": false,
"tilt": false,
"labels": true,
"arrangement": "horizontal",
"chart": "table",
"counter_pos": "above",
"spyable": true,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"tmode": "terms",
"tstat": "total",
"valuefield": "",
"title": "Per City Downloads"
},
{
"error": false,
"span": 4,
"editable": true,
"type": "terms",
"loadingEditor": false,
"field": "geoip.country_name.raw",
"exclude": [],
"missing": false,
"other": false,
"size": 10,
"order": "count",
"style": {
"font-size": "10pt"
},
"donut": false,
"tilt": false,
"labels": true,
"arrangement": "horizontal",
"chart": "table",
"counter_pos": "above",
"spyable": true,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"tmode": "terms",
"tstat": "total",
"valuefield": "",
"title": "Per Country Downloads"
},
{
"error": false,
"span": 4,
"editable": true,
"type": "terms",
"loadingEditor": false,
"field": "http.hostname",
"exclude": [],
"missing": false,
"other": false,
"size": 10,
"order": "count",
"style": {
"font-size": "10pt"
},
"donut": false,
"tilt": false,
"labels": true,
"arrangement": "horizontal",
"chart": "table",
"counter_pos": "above",
"spyable": true,
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"tmode": "terms",
"tstat": "total",
"valuefield": "",
"title": "HTTP Hostname"
}
],
"notice": false
},
{
"notice": false,
"collapsable": true,
"collapse": false,
"title": "Events",
"editable": true,
"height": "350px",
"panels": [
{
"header": true,
"trimFactor": 300,
"spyable": true,
"field_list": true,
"size": 100,
"all_fields": true,
"style": {
"font-size": "9pt"
},
"span": 12,
"title": "ALL Details",
"pages": 5,
"loadingEditor": false,
"type": "table",
"sort": [
"@timestamp",
"desc"
],
"queries": {
"mode": "all",
"ids": [
0,
1,
2,
3,
4,
5,
6
]
},
"editable": true,
"offset": 0,
"overflow": "min-height",
"normTimes": true,
"localTime": false,
"sortable": true,
"fields": [
"timestamp",
"dest_ip",
"src_ip",
"src_port",
"dest_port",
"type",
"geoip.city_name"
],
"paging": true,
"error": false,
"timeField": "@timestamp",
"highlight": []
}
]
}
],
"title": "Suricata - ALL",
"failover": false,
"editable": true,
"refresh": "5m",
"loader": {
"load_gist": true,
"hide": false,
"save_temp": true,
"load_elasticsearch_size": 20,
"load_local": true,
"save_temp_ttl": "30d",
"load_elasticsearch": true,
"save_local": true,
"save_temp_ttl_enable": true,
"save_elasticsearch": true,
"save_gist": false,
"save_default": true
},
"pulldowns": [
{
"notice": false,
"enable": true,
"collapse": true,
"pinned": true,
"query": "*",
"history": [
"event_type:\"smtp\"",
"event_type:\"ssh\"",
"event_type:\"http\"",
"event_type:\"dns\"",
"event_type:\"tls\"",
"event_type:\"fileinfo\"",
"event_type:\"alert\"",
"http*",
"*",
"tls*"
],
"type": "query",
"remember": 10
},
{
"notice": false,
"enable": true,
"type": "filtering",
"collapse": true
}
],
"nav": [
{
"status": "Stable",
"notice": false,
"enable": true,
"collapse": false,
"time_options": [
"5m",
"15m",
"1h",
"6h",
"12h",
"24h",
"2d",
"7d",
"30d"
],
"refresh_intervals": [
"5s",
"10s",
"30s",
"1m",
"5m",
"15m",
"30m",
"1h",
"2h",
"1d"
],
"filter_id": 0,
"timefield": "@timestamp",
"now": true,
"type": "timepicker"
}
],
"services": {
"filter": {
"list": {
"0": {
"type": "time",
"field": "@timestamp",
"from": "now-1h",
"to": "now",
"mandate": "must",
"active": true,
"alias": "",
"id": 0
},
"1": {
"type": "querystring",
"query": "type:pfSense_Suricata",
"mandate": "must",
"active": true,
"alias": "",
"id": 1
}
},
"ids": [
0,
1
],
"idQueue": [
1
]
},
"query": {
"list": {
"0": {
"enable": true,
"pin": true,
"color": "#BF1B00",
"alias": "Alerts",
"query": "event_type:\"alert\"",
"type": "lucene",
"id": 0
},
"1": {
"enable": true,
"pin": true,
"color": "#0A437C",
"alias": "Files",
"query": "event_type:\"fileinfo\"",
"type": "lucene",
"id": 1
},
"2": {
"enable": true,
"pin": true,
"color": "#E5A8E2",
"alias": "TLS",
"query": "event_type:\"tls\"",
"type": "lucene",
"id": 2
},
"3": {
"enable": true,
"pin": true,
"color": "#7EB26D",
"alias": "DNS",
"query": "event_type:\"dns\"",
"type": "lucene",
"id": 3
},
"4": {
"enable": true,
"pin": true,
"color": "#70DBED",
"alias": "HTTP",
"query": "event_type:\"http\"",
"type": "lucene",
"id": 4
},
"5": {
"enable": true,
"pin": true,
"color": "#EAB839",
"alias": "SSH",
"query": "event_type:\"ssh\"",
"type": "lucene",
"id": 5
},
"6": {
"id": 6,
"color": "#BA43A9",
"alias": "SMTP",
"pin": true,
"type": "lucene",
"enable": true,
"query": "event_type:\"smtp\""
}
},
"ids": [
0,
1,
2,
3,
4,
5,
6
],
"idQueue": []
}
},
"panel_hints": true
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment