Skip to content

Instantly share code, notes, and snippets.

@evoxco
Last active September 8, 2015 17:35
Show Gist options
  • Save evoxco/94a355868972c557aa3a to your computer and use it in GitHub Desktop.
Save evoxco/94a355868972c557aa3a to your computer and use it in GitHub Desktop.
Nprobe flow Qbana Dashboard
{
"index": {
"default": "_all",
"pattern": "[nprobe-]YYYY.MM.DD",
"warm_fields": true,
"interval": "day"
},
"style": "light",
"rows": [
{
"notice": false,
"panels": [
{
"error": false,
"span": 2,
"editable": true,
"type": "text",
"loadingEditor": false,
"mode": "html",
"content": "<img src=\"http://ntop.qxip.net/qbana/img/qb.png\" height=\"20%\" width=\"20%\">\n<br><br>\nThis dashboard requires <b>nProbe</b>. Download your copy from <a href=\"http://ntop.org\" target=\"_blank\">ntop.org</a>",
"style": {},
"title": "qb"
},
{
"show_query": true,
"bars": true,
"interval": "1m",
"zoomlinks": true,
"annotate": {
"sort": [
"_score",
"desc"
],
"query": "*",
"enable": false,
"field": "_type",
"size": 20
},
"intervals": [
"auto",
"1s",
"1m",
"5m",
"10m",
"30m",
"1h",
"3h",
"12h",
"1d",
"1w",
"1y"
],
"timezone": "browser",
"spyable": true,
"linewidth": 3,
"percentage": false,
"fill": 0,
"scale": 1,
"span": 10,
"title": "Transactions per min",
"tooltip": {
"query_as_alias": true,
"value_type": "cumulative"
},
"stack": true,
"derivative": false,
"loadingEditor": false,
"auto_int": false,
"type": "histogram",
"value_field": null,
"x-axis": true,
"pointradius": 5,
"editable": true,
"zerofill": true,
"grid": {
"max": null,
"min": 0
},
"legend": true,
"legend_counts": true,
"time_field": "@timestamp",
"y-axis": true,
"lines": false,
"y_format": "none",
"points": false,
"mode": "count",
"queries": {
"mode": "selected",
"ids": [
3
]
},
"resolution": 100,
"options": true,
"interactive": true
}
],
"collapse": false,
"title": "Graph",
"editable": true,
"height": "100px",
"collapsable": true
},
{
"title": "Breakdown",
"height": "150px",
"editable": true,
"collapse": false,
"collapsable": true,
"panels": [
{
"error": false,
"span": 12,
"editable": true,
"type": "terms",
"loadingEditor": false,
"field": "L7_PROTO_NAME",
"exclude": [],
"missing": false,
"other": true,
"size": 10,
"order": "count",
"style": {
"font-size": "10pt"
},
"donut": false,
"tilt": false,
"labels": true,
"arrangement": "horizontal",
"chart": "bar",
"counter_pos": "above",
"spyable": true,
"queries": {
"mode": "selected",
"ids": [
3
]
},
"tmode": "terms",
"tstat": "total",
"valuefield": "",
"title": "Protocol Breakdown",
"tsums": false,
"dtype": ""
}
],
"notice": false
},
{
"title": "Test",
"height": "350px",
"editable": true,
"collapse": false,
"collapsable": true,
"panels": [
{
"error": false,
"span": 10,
"editable": true,
"type": "flows",
"loadingEditor": false,
"spyable": true,
"size": 20,
"exclude": [],
"tmode": "terms",
"chart": "flows",
"style": {
"font-size": "16pt"
},
"queries": {
"mode": "selected",
"ids": [
3
]
},
"title": "Comm Flow",
"src_field": "IPV4_SRC_ADDR",
"dst_field": "IPV4_DST_ADDR"
}
],
"notice": false
},
{
"title": "Fancy",
"height": "350px",
"editable": true,
"collapse": false,
"collapsable": true,
"panels": [
{
"error": false,
"span": 6,
"editable": true,
"type": "force",
"loadingEditor": false,
"spyable": true,
"size": 200,
"queries": {
"mode": "selected",
"ids": [
3
]
},
"title": "Mash",
"src_field": "IPV4_SRC_ADDR",
"dst_field": "IPV4_DST_ADDR"
},
{
"error": false,
"span": 6,
"editable": true,
"type": "force",
"loadingEditor": false,
"spyable": true,
"size": 200,
"queries": {
"mode": "selected",
"ids": [
3
]
},
"title": "Mash",
"src_field": "IPV4_SRC_ADDR",
"dst_field": "L7_PROTO_NAME"
}
],
"notice": false
},
{
"notice": false,
"panels": [
{
"sort": [
"@timestamp",
"desc"
],
"header": true,
"trimFactor": 300,
"spyable": true,
"field_list": true,
"size": 50,
"all_fields": false,
"style": {
"font-size": "9pt"
},
"span": 12,
"title": "Transactions",
"pages": 10,
"loadingEditor": false,
"type": "table",
"status": "Stable",
"error": false,
"editable": true,
"offset": 0,
"group": "default",
"overflow": "min-height",
"normTimes": true,
"localTime": false,
"sortable": true,
"fields": [
"@timestamp",
"L7_PROTO_NAME",
"IPV4_SRC_ADDR",
"L4_SRC_PORT",
"IPV4_DST_ADDR",
"L4_DST_PORT",
"IN_BYTES",
"OUT_BYTES"
],
"paging": true,
"queries": {
"mode": "all",
"ids": [
0,
3
]
},
"timeField": "@timestamp",
"highlight": []
}
],
"collapse": false,
"title": "Transactions",
"editable": true,
"height": "150px",
"collapsable": true
}
],
"title": "nProbe - Flow Search",
"failover": true,
"editable": true,
"refresh": false,
"loader": {
"load_gist": true,
"hide": false,
"save_temp": true,
"load_elasticsearch_size": 20,
"load_local": true,
"save_temp_ttl": "30d",
"load_elasticsearch": true,
"save_local": true,
"save_elasticsearch": true,
"save_temp_ttl_enable": true,
"save_gist": false,
"save_default": true
},
"pulldowns": [
{
"notice": false,
"enable": true,
"collapse": true,
"remember": 10,
"pinned": true,
"query": "*",
"type": "query",
"history": [
"_type:nProbe",
"IPV4_SRC_ADDR:\"172.27.28.55\"",
"_type:ip",
"term:{\"_type\":\"ip\"}",
"172.27.28.55",
"type:nProbe",
"*"
]
},
{
"notice": false,
"enable": true,
"type": "filtering",
"collapse": true
}
],
"nav": [
{
"notice": false,
"enable": true,
"collapse": false,
"dashboards": [
"Broids",
"Broids-C1fApp Intel",
"Broids-HTTP",
"nProbe - Flow Search",
"nProbe - HTTP Search"
],
"label": "Page: ",
"type": "dashboard_dropdown"
},
{
"status": "Stable",
"notice": false,
"enable": true,
"collapse": false,
"time_options": [
"5m",
"15m",
"1h",
"6h",
"12h",
"24h",
"2d",
"7d",
"30d"
],
"refresh_intervals": [
"5s",
"10s",
"30s",
"1m",
"5m",
"15m",
"30m",
"1h",
"2h",
"1d"
],
"filter_id": 0,
"timefield": "@timestamp",
"now": true,
"type": "timepicker"
}
],
"services": {
"filter": {
"list": {
"0": {
"type": "time",
"field": "@timestamp",
"from": "now-6h",
"to": "now",
"mandate": "must",
"active": true,
"alias": "",
"id": 0
},
"1": {
"type": "terms",
"field": "IPV4_DST_ADDR",
"value": "37.99.196.24",
"mandate": "must",
"active": false,
"alias": "",
"id": 1
}
},
"ids": [
0,
1
],
"idQueue": [
0,
1,
2
]
},
"query": {
"list": {
"0": {
"id": 0,
"color": "#7EB26D",
"alias": "IP for Flare",
"pin": true,
"type": "lucene",
"enable": true,
"query": "IPV4_SRC_ADDR:\"172.27.28.55\""
},
"3": {
"enable": true,
"pin": false,
"color": "#EA6460",
"alias": "",
"query": "_type:nProbe",
"type": "lucene",
"id": 3
}
},
"ids": [
0,
3
],
"idQueue": [
1,
2,
3,
4
]
}
},
"panel_hints": true
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment