Reply
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Highlighted
2078    
0
ADP Events by Source IP with drilldown (using lookup table)
Options
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
01-18-2016 07:59 PM
This report contains information about ADP events split by IP. It allows to navigate to "ADP Events by Rule" and drilldown to the same report with different IP/Rule parameters.
This report doesn't contain rule name/severity information because my 7.3EA Grid doesn't include any PT-appliance and a lookup table is missing. The lookup table "atp_rule_sid_lookup.csv" is automatically generated from ADP rules. In the next post I created the same report using a workaround.
Report ID: pvm_adp_rules_hits_by_client
<form> <label>1_ADP Rules Hits by Clients</label> <fieldset submitButton="false" autoRun="true"> <input type="time" token="time" searchWhenChanged="true"> <label>Period</label> <default> <earliest>-30d@d</earliest> <latest>now</latest> </default> </input> <input type="text" token="Client"> <default>*</default> </input> <input type="text" token="RuleID"> <default>*</default> </input> </fieldset> <row> <panel> <table> <search> <query>index=ib_security source="ib:ddos:ip_rule_stats" SOURCE_IP="$Client$" RULE_SID="$RuleID$" | stats sum(ACTIVE_COUNT) as Qty by SOURCE_IP, RULE_SID |lookup atp_rule_sid_lookup RULE_SID OUTPUTNEW RULE_SID as SID, DNST_CATEGORY as CATEGORY, RULE_DESCRIPTION as DESCRIPTION, RULE_NAME as NAME | sort Qty desc</query> <earliest>$time.earliest$</earliest> <latest>$time.latest$</latest> </search> <drilldown> <condition field="MESSAGE"> <link target="_blank">/app/infoblox/pvm_adp_rules_hits_by_client?form.RuleID=$row.RULE_SID$&form.time.earliest=$time.earliest$&form.time.latest=$time.latest$&form.time=$time$</link> </condition> <condition field="SOURCE_IP"> <link target="_blank">/app/infoblox/pvm_adp_rules_hits_by_client?form.Client=$row.SOURCE_IP$&form.time.earliest=$time.earliest$&form.time.latest=$time.latest$&form.time=$time$</link> </condition> <condition field="CATEGORY"> <link target="_blank">/app/infoblox/pvm_adp_rules?form.Category=$row.CATEGORY$&form.time.earliest=$time.earliest$&form.time.latest=$time.latest$&form.time=$time$</link> </condition> </drilldown> <option name="fields">SOURCE_IP,SID,NAME,DESCRIPTION,SEVERITY,Qty</option> <option name="wrap">true</option> <option name="rowNumbers">false</option> <option name="dataOverlayMode">none</option> <option name="drilldown">cell</option> <option name="count">10</option> <fields>["SOURCE_IP","RULE_SID","NAME","DESCRIPTION","SEVERITY","Qty"]</fields> </table> </panel> </row> </form>