File: //usr/share/auditbeat/kibana/7/visualization/a8e20450-c256-11e7-8692-232bd1143e8a-ecs.json
{
"attributes": {
"description": "",
"kibanaSavedObjectMeta": {
"searchSourceJSON": {
"filter": [],
"indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.index",
"query": {
"language": "kuery",
"query": ""
}
}
},
"title": "Socket Families [Auditbeat Auditd] ECS",
"uiStateJSON": {},
"version": 1,
"visState": {
"aggs": [
{
"enabled": true,
"id": "1",
"params": {},
"schema": "metric",
"type": "count"
},
{
"enabled": true,
"id": "2",
"params": {
"customLabel": "Socket Family",
"field": "auditd.data.socket.family",
"order": "desc",
"orderBy": "1",
"size": 10
},
"schema": "segment",
"type": "terms"
},
{
"enabled": true,
"id": "3",
"params": {
"customLabel": "Syscall",
"field": "auditd.data.syscall",
"order": "desc",
"orderBy": "1",
"size": 10
},
"schema": "segment",
"type": "terms"
}
],
"params": {
"addLegend": true,
"addTooltip": true,
"distinctColors": true,
"isDonut": true,
"legendPosition": "left",
"palette": {
"name": "kibana_palette",
"type": "palette"
},
"type": "pie"
},
"title": "Socket Families [Auditbeat Auditd] ECS",
"type": "pie"
}
},
"coreMigrationVersion": "8.0.0",
"id": "a8e20450-c256-11e7-8692-232bd1143e8a-ecs",
"migrationVersion": {
"visualization": "7.14.0"
},
"references": [
{
"id": "auditbeat-*",
"name": "kibanaSavedObjectMeta.searchSourceJSON.index",
"type": "index-pattern"
}
],
"type": "visualization",
"updated_at": "2021-08-04T16:35:59.895Z",
"version": "WzQ5NzksMV0="
}