File: //usr/share/filebeat/kibana/8/visualization/cef-509321f8-3864-4435-8ca7-7e9b0fd382e0.json
{
"attributes": {
"description": "",
"kibanaSavedObjectMeta": {
"searchSourceJSON": {
"filter": []
}
},
"savedSearchRefName": "search_0",
"title": "DNS Metrics Overview — ArcSight [Filebeat CEF]",
"uiStateJSON": {
"vis": {
"defaultColors": {
"0 - 100": "rgb(0,104,55)"
}
}
},
"version": 1,
"visState": {
"aggs": [
{
"enabled": true,
"id": "5",
"params": {
"customLabel": "Event Count"
},
"schema": "metric",
"type": "count"
},
{
"enabled": true,
"id": "2",
"params": {
"customLabel": "Threads",
"field": "cef.extensions.deviceCustomString1"
},
"schema": "metric",
"type": "cardinality"
},
{
"enabled": true,
"id": "3",
"params": {
"customLabel": "OpCodes",
"field": "cef.extensions.deviceCustomString2"
},
"schema": "metric",
"type": "cardinality"
},
{
"enabled": true,
"id": "4",
"params": {
"customLabel": "Activity Types",
"field": "cef.device.event_class_id"
},
"schema": "metric",
"type": "cardinality"
}
],
"listeners": {},
"params": {
"addLegend": false,
"addTooltip": true,
"gauge": {
"autoExtend": false,
"backStyle": "Full",
"colorSchema": "Green to Red",
"colorsRange": [
{
"from": 0,
"to": 100
}
],
"gaugeColorMode": "None",
"gaugeStyle": "Full",
"gaugeType": "Metric",
"invertColors": false,
"labels": {
"color": "black",
"show": true
},
"orientation": "vertical",
"percentageMode": false,
"scale": {
"color": "#333",
"labels": false,
"show": false,
"width": 2
},
"style": {
"bgColor": false,
"bgFill": "#000",
"fontSize": "32",
"labelColor": false,
"subText": ""
},
"type": "simple",
"useRange": false,
"verticalSplit": false
},
"type": "gauge"
},
"title": "DNS Metrics Overview — ArcSight [Filebeat CEF]",
"type": "metric"
}
},
"coreMigrationVersion": "8.3.3",
"id": "cef-509321f8-3864-4435-8ca7-7e9b0fd382e0",
"migrationVersion": {
"visualization": "8.3.0"
},
"references": [
{
"id": "cef-721d1d17-9c3a-4002-9f23-d51a12604d41",
"name": "search_0",
"type": "search"
}
],
"type": "visualization",
"updated_at": "2022-08-24T00:29:51.550Z",
"version": "WzIzOTcsMV0="
}