{
"attributes": {
"description": "",
"kibanaSavedObjectMeta": {
"searchSourceJSON": {
"filter": []
}
},
"savedSearchRefName": "search_0",
"title": "New users [Filebeat System] ECS",
"uiStateJSON": {
"vis": {
"params": {
"sort": {
"columnIndex": null,
"direction": null
}
}
}
},
"version": 1,
"visState": {
"aggs": [
{
"enabled": true,
"id": "1",
"params": {},
"schema": "metric",
"type": "count"
},
{
"enabled": true,
"id": "2",
"params": {
"customLabel": "Host",
"field": "host.hostname",
"order": "desc",
"orderBy": "1",
"size": 5
},
"schema": "bucket",
"type": "terms"
},
{
"enabled": true,
"id": "3",
"params": {
"customLabel": "User",
"field": "user.name",
"order": "desc",
"orderBy": "1",
"size": 5
},
"schema": "bucket",
"type": "terms"
},
{
"enabled": true,
"id": "4",
"params": {
"customLabel": "UID",
"field": "user.id",
"order": "desc",
"orderBy": "1",
"size": 5
},
"schema": "bucket",
"type": "terms"
},
{
"enabled": true,
"id": "5",
"params": {
"customLabel": "GID",
"field": "group.id",
"order": "desc",
"orderBy": "1",
"size": 5
},
"schema": "bucket",
"type": "terms"
},
{
"enabled": true,
"id": "6",
"params": {
"customLabel": "Home",
"field": "system.auth.useradd.home",
"order": "desc",
"orderBy": "1",
"size": 5
},
"schema": "bucket",
"type": "terms"
},
{
"enabled": true,
"id": "7",
"params": {
"customLabel": "Shell",
"field": "system.auth.useradd.shell",
"order": "desc",
"orderBy": "1",
"size": 5
},
"schema": "bucket",
"type": "terms"
}
],
"listeners": {},
"params": {
"perPage": 10,
"showMeticsAtAllLevels": false,
"showPartialRows": false,
"showToolbar": true,
"showTotal": false,
"sort": {
"columnIndex": null,
"direction": null
},
"totalFunc": "sum"
},
"title": "New users ECS",
"type": "table"
}
},
"coreMigrationVersion": "8.0.0",
"id": "f398d2f0-fa77-11e6-ae9b-81e5311e8cab-ecs",
"migrationVersion": {
"visualization": "7.14.0"
},
"references": [
{
"id": "8030c1b0-fa77-11e6-ae9b-81e5311e8cab-ecs",
"name": "search_0",
"type": "search"
}
],
"type": "visualization",
"updated_at": "2021-08-04T16:34:15.759Z",
"version": "WzQ0NzIsMV0="
}