Skip to content

Commit ab90613

Browse files
committed
Merge branch 'development' of https://github.com/mmguero-dev/Malcolm into v24.10.0_merge_idaholab
2 parents 2f94ef9 + 7260e20 commit ab90613

File tree

92 files changed

+453
-311
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

92 files changed

+453
-311
lines changed

.github/workflows/hedgehog-iso-build-docker-wrap-push-ghcr.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,7 @@ jobs:
129129
echo "${{ steps.extract_malcolm_version.outputs.mversion }}" > ./shared/version.txt
130130
echo "${{ secrets.MAXMIND_GEOIP_DB_LICENSE_KEY }}" > ./shared/maxmind_license.txt
131131
echo "${{ secrets.MAXMIND_GEOIP_DB_ALTERNATE_DOWNLOAD_URL }}" > ./shared/maxmind_url.txt
132+
echo "${{ secrets.ZEEK_DEB_ALTERNATE_DOWNLOAD_URL }}" > ./shared/zeek_url.txt
132133
echo "GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }}" > ./shared/environment.chroot
133134
echo "VCS_REVSION=${{ steps.extract_commit_sha.outputs.sha }}" > ./shared/environment.chroot
134135
echo "BUILD_JOBS=2" > ./shared/environment.chroot

.github/workflows/hedgehog-raspi-build-docker-wrap-push-ghcr.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -86,6 +86,7 @@ jobs:
8686
echo "${{ steps.extract_malcolm_version.outputs.mversion }}" > ./shared/version.txt
8787
echo "${{ secrets.MAXMIND_GEOIP_DB_LICENSE_KEY }}" > ./shared/maxmind_license.txt
8888
echo "${{ secrets.MAXMIND_GEOIP_DB_ALTERNATE_DOWNLOAD_URL }}" > ./shared/maxmind_url.txt
89+
echo "${{ secrets.ZEEK_DEB_ALTERNATE_DOWNLOAD_URL }}" > ./shared/zeek_url.txt
8990
echo "GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }}" > ./shared/environment.chroot
9091
echo "VCS_REVSION=${{ steps.extract_commit_sha.outputs.sha }}" > ./shared/environment.chroot
9192
echo "BUILD_JOBS=2" > ./shared/environment.chroot

.github/workflows/zeek-build-and-push-ghcr.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -105,6 +105,7 @@ jobs:
105105
MALCOLM_VERSION=${{ steps.extract_malcolm_version.outputs.mversion }}
106106
BUILD_DATE=${{ steps.generate_build_timestamp.outputs.btimestamp }}
107107
VCS_REVISION=${{ steps.extract_commit_sha.outputs.sha }}
108+
ZEEK_DEB_ALTERNATE_DOWNLOAD_URL=${{ secrets.ZEEK_DEB_ALTERNATE_DOWNLOAD_URL }}
108109
push: true
109110
provenance: false
110111
platforms: ${{ matrix.platform }}

Dockerfiles/arkime.Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,7 @@ RUN export DEBARCH=$(dpkg --print-architecture) && \
149149
mkdir -p "${ARKIME_DIR}"/plugins && \
150150
curl -fsSL -o "${ARKIME_DIR}/plugins/ja4plus.${DEBARCH}.so" "$(echo "${ARKIME_JA4_SO_URL}" | sed "s/XXX/${DEBARCH}/g")" && \
151151
chmod 755 "${ARKIME_DIR}/plugins/ja4plus.${DEBARCH}.so" && \
152-
python3 -m pip install --break-system-packages --no-compile --no-cache-dir beautifulsoup4 pyzmq watchdog==5.0.2 && \
152+
python3 -m pip install --break-system-packages --no-compile --no-cache-dir beautifulsoup4 pyzmq watchdog==5.0.3 && \
153153
ln -sfr $ARKIME_DIR/bin/npm /usr/local/bin/npm && \
154154
ln -sfr $ARKIME_DIR/bin/node /usr/local/bin/node && \
155155
ln -sfr $ARKIME_DIR/bin/npx /usr/local/bin/npx && \

Dockerfiles/dashboards.Dockerfile

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM opensearchproject/opensearch-dashboards:2.17.0
1+
FROM opensearchproject/opensearch-dashboards:2.17.1
22

33
LABEL maintainer="malcolm@inl.gov"
44
LABEL org.opencontainers.image.authors='malcolm@inl.gov'
@@ -23,7 +23,7 @@ ENV TERM xterm
2323
ENV TINI_VERSION v0.19.0
2424
ENV TINI_URL https://github.com/krallin/tini/releases/download/${TINI_VERSION}/tini
2525

26-
ENV OSD_TRANSFORM_VIS_VERSION 2.16.0
26+
ENV OSD_TRANSFORM_VIS_VERSION 2.17.1
2727

2828
ARG NODE_OPTIONS="--max_old_space_size=4096"
2929
ENV NODE_OPTIONS $NODE_OPTIONS
@@ -42,10 +42,10 @@ RUN export BINARCH=$(uname -m | sed 's/x86_64/amd64/' | sed 's/aarch64/arm64/')
4242
# Malcolm manages authentication and encryption via NGINX reverse proxy
4343
/usr/share/opensearch-dashboards/bin/opensearch-dashboards-plugin remove securityDashboards --allow-root && \
4444
cd /tmp && \
45-
unzip transformVis.zip opensearch-dashboards/transformVis/opensearch_dashboards.json opensearch-dashboards/transformVis/package.json && \
46-
sed -i "s/2\.16\.0/2\.17\.0/g" opensearch-dashboards/transformVis/opensearch_dashboards.json && \
47-
sed -i "s/2\.16\.0/2\.17\.0/g" opensearch-dashboards/transformVis/package.json && \
48-
zip transformVis.zip opensearch-dashboards/transformVis/opensearch_dashboards.json opensearch-dashboards/transformVis/package.json && \
45+
# unzip transformVis.zip opensearch-dashboards/transformVis/opensearch_dashboards.json opensearch-dashboards/transformVis/package.json && \
46+
# sed -i "s/2\.16\.0/2\.17\.0/g" opensearch-dashboards/transformVis/opensearch_dashboards.json && \
47+
# sed -i "s/2\.16\.0/2\.17\.0/g" opensearch-dashboards/transformVis/package.json && \
48+
# zip transformVis.zip opensearch-dashboards/transformVis/opensearch_dashboards.json opensearch-dashboards/transformVis/package.json && \
4949
cd /usr/share/opensearch-dashboards/plugins && \
5050
/usr/share/opensearch-dashboards/bin/opensearch-dashboards-plugin install file:///tmp/transformVis.zip --allow-root && \
5151
rm -rf /tmp/transformVis /tmp/opensearch-dashboards && \

Dockerfiles/file-monitor.Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -159,7 +159,7 @@ RUN export BINARCH=$(uname -m | sed 's/x86_64/amd64/' | sed 's/aarch64/arm64/')
159159
python-magic \
160160
stream-zip \
161161
supervisor \
162-
watchdog==5.0.2 \
162+
watchdog==5.0.3 \
163163
yara-python && \
164164
curl -fsSL -o /usr/local/bin/supercronic "${SUPERCRONIC_URL}${BINARCH}" && \
165165
chmod +x /usr/local/bin/supercronic && \

Dockerfiles/filebeat.Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM docker.elastic.co/beats/filebeat-oss:8.15.1
1+
FROM docker.elastic.co/beats/filebeat-oss:8.15.2
22

33
# Copyright (c) 2024 Battelle Energy Alliance, LLC. All rights reserved.
44
LABEL maintainer="malcolm@inl.gov"
@@ -108,7 +108,7 @@ RUN export EVTXARCH=$(uname -m | sed 's/arm64/aarch64/') && \
108108
unzip \
109109
xz-utils && \
110110
ln -s -f -r /usr/bin/python3.9 /usr/bin/python3 && \
111-
python3.9 -m pip install --no-compile --no-cache-dir patool entrypoint2 pyunpack python-magic ordered-set supervisor watchdog==5.0.2 && \
111+
python3.9 -m pip install --no-compile --no-cache-dir patool entrypoint2 pyunpack python-magic ordered-set supervisor watchdog==5.0.3 && \
112112
curl -fsSL -o /usr/local/bin/supercronic "${SUPERCRONIC_URL}${BINARCH}" && \
113113
chmod +x /usr/local/bin/supercronic && \
114114
curl -fsSL -o /usr/local/bin/yq "${YQ_URL}${BINARCH}" && \

Dockerfiles/logstash.Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM docker.elastic.co/logstash/logstash-oss:8.15.1
1+
FROM docker.elastic.co/logstash/logstash-oss:8.15.2
22

33
LABEL maintainer="malcolm@inl.gov"
44
LABEL org.opencontainers.image.authors='malcolm@inl.gov'

Dockerfiles/opensearch.Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM opensearchproject/opensearch:2.17.0
1+
FROM opensearchproject/opensearch:2.17.1
22

33
# Copyright (c) 2024 Battelle Energy Alliance, LLC. All rights reserved.
44
LABEL maintainer="malcolm@inl.gov"

Dockerfiles/pcap-monitor.Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ RUN apt-get -q update && \
6767
python-magic \
6868
pyzmq \
6969
requests \
70-
watchdog==5.0.2 && \
70+
watchdog==5.0.3 && \
7171
groupadd --gid ${DEFAULT_GID} ${PGROUP} && \
7272
useradd -M --uid ${DEFAULT_UID} --gid ${DEFAULT_GID} ${PUSER}
7373

Dockerfiles/suricata.Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,7 @@ RUN export BINARCH=$(uname -m | sed 's/x86_64/amd64/' | sed 's/aarch64/arm64/')
108108
apt-get install -q -y --no-install-recommends -t bookworm-backports \
109109
suricata=${SURICATA_VERSION_PATTERN} \
110110
suricata-update && \
111-
python3 -m pip install --break-system-packages --no-compile --no-cache-dir watchdog==5.0.2 && \
111+
python3 -m pip install --break-system-packages --no-compile --no-cache-dir watchdog==5.0.3 && \
112112
curl -fsSL -o /usr/local/bin/supercronic "${SUPERCRONIC_URL}${BINARCH}" && \
113113
chmod +x /usr/local/bin/supercronic && \
114114
curl -fsSL -o /usr/bin/yq "${YQ_URL}${BINARCH}" && \

Dockerfiles/zeek.Dockerfile

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,8 +33,9 @@ USER root
3333
# see PUSER_CHOWN at the bottom of the file (after the other environment variables it references)
3434

3535
# for download and install
36-
ARG ZEEK_VERSION=7.0.1-0
36+
ARG ZEEK_VERSION=7.0.3-0
3737
ENV ZEEK_VERSION $ZEEK_VERSION
38+
ARG ZEEK_DEB_ALTERNATE_DOWNLOAD_URL=""
3839

3940
# put Zeek and Spicy in PATH
4041
ENV ZEEK_DIR "/opt/zeek"
@@ -246,6 +247,7 @@ ARG ZEEK_DISABLE_HASH_ALL_FILES=
246247
ARG ZEEK_DISABLE_LOG_PASSWORDS=
247248
ARG ZEEK_DISABLE_SSL_VALIDATE_CERTS=
248249
ARG ZEEK_DISABLE_TRACK_ALL_ASSETS=
250+
ARG ZEEK_DISABLE_DETECT_ROUTERS=true
249251
ARG ZEEK_DISABLE_BEST_GUESS_ICS=true
250252
# TODO: assess spicy-analyzer that replace built-in Zeek parsers
251253
# for now, disable them by default when a Zeek parser exists
@@ -264,6 +266,7 @@ ENV ZEEK_DISABLE_HASH_ALL_FILES $ZEEK_DISABLE_HASH_ALL_FILES
264266
ENV ZEEK_DISABLE_LOG_PASSWORDS $ZEEK_DISABLE_LOG_PASSWORDS
265267
ENV ZEEK_DISABLE_SSL_VALIDATE_CERTS $ZEEK_DISABLE_SSL_VALIDATE_CERTS
266268
ENV ZEEK_DISABLE_TRACK_ALL_ASSETS $ZEEK_DISABLE_TRACK_ALL_ASSETS
269+
ENV ZEEK_DISABLE_DETECT_ROUTERS $ZEEK_DISABLE_DETECT_ROUTERS
267270
ENV ZEEK_DISABLE_BEST_GUESS_ICS $ZEEK_DISABLE_BEST_GUESS_ICS
268271

269272
ENV ZEEK_DISABLE_SPICY_IPSEC $ZEEK_DISABLE_SPICY_IPSEC

api/project/__init__.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -743,7 +743,7 @@ def fields():
743743
s = SearchClass(
744744
using=databaseClient,
745745
index=index_from_args(args),
746-
).extra(size=5000)
746+
).extra(size=6000)
747747
for hit in [x['_source'] for x in s.execute().to_dict().get('hits', {}).get('hits', [])]:
748748
if (fieldname := malcolm_utils.deep_get(hit, ['dbField2'])) and (fieldname not in fields):
749749
if debugApi:

api/requirements.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,5 +6,5 @@ requests==2.32.0
66
regex==2022.3.2
77
dateparser==1.1.1
88
elasticsearch==8.15.1
9-
elasticsearch-dsl==8.15.3
9+
elasticsearch-dsl==8.15.4
1010
psutil==5.9.8

arkime/etc/config.ini

Lines changed: 7 additions & 1 deletion
Large diffs are not rendered by default.

arkime/wise/source.zeeklogs.js

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1638,10 +1638,11 @@ class MalcolmSource extends WISESource {
16381638
"zeek.hart_ip_universal_commands.write_tag_descriptor_date_date_code",
16391639
"zeek.hart_ip_universal_commands.write_tag_descriptor_date_record_keeping_descriptor",
16401640
"zeek.hart_ip_universal_commands.write_tag_descriptor_date_tag",
1641+
"zeek.http.client_header_names",
16411642
"zeek.http.host",
1642-
"zeek.http.ja4h",
16431643
"zeek.http.info_code",
16441644
"zeek.http.info_msg",
1645+
"zeek.http.ja4h",
16451646
"zeek.http.method",
16461647
"zeek.http.orig_filenames",
16471648
"zeek.http.orig_fuids",
@@ -1656,6 +1657,7 @@ class MalcolmSource extends WISESource {
16561657
"zeek.http.resp_fuids",
16571658
"zeek.http.resp_mime_types",
16581659
"zeek.http.response_body_len",
1660+
"zeek.http.server_header_names",
16591661
"zeek.http.status_code",
16601662
"zeek.http.status_msg",
16611663
"zeek.http.tags",
@@ -1727,6 +1729,8 @@ class MalcolmSource extends WISESource {
17271729
"zeek.known_certs.serial",
17281730
"zeek.known_certs.subject",
17291731
"zeek.known_modbus.device_type",
1732+
"zeek.known_routers.ttl",
1733+
"zeek.known_routers.hlim",
17301734
"zeek.ldap.argument",
17311735
"zeek.ldap.message_id",
17321736
"zeek.ldap.object",

config/zeek.env.example

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,7 @@ ZEEK_DISABLE_HASH_ALL_FILES=
6868
ZEEK_DISABLE_LOG_PASSWORDS=
6969
ZEEK_DISABLE_SSL_VALIDATE_CERTS=
7070
ZEEK_DISABLE_TRACK_ALL_ASSETS=
71+
ZEEK_DISABLE_DETECT_ROUTERS=true
7172
ZEEK_DISABLE_SPICY_IPSEC=
7273
ZEEK_DISABLE_SPICY_LDAP=
7374
ZEEK_DISABLE_SPICY_OPENVPN=

dashboards/dashboards/024062a6-48d6-498f-a91a-3bf2da3a3cd3.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/0a490422-0ce9-44bf-9a2d-19329ddde8c3.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/11be6381-beef-40a7-bdce-88c5398392fc.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/11ddd980-e388-11e9-b568-cf17de8e860c.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/1fff49f6-0199-4a0f-820b-721aff9ff1f1.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/2cf94cd0-ecab-40a5-95a7-8419f3a39cd9.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/432af556-c5c0-4cc3-8166-b274b4e3a406.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/50ced171-1b10-4c3f-8b67-2db9635661a6.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/543118a9-02d7-43fe-b669-b8652177fc37.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/7f41913f-cba8-43f5-82a8-241b7ead03e0.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/92985909-dc29-4533-9e80-d3182a0ecf1d.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/a7514350-eba6-11e9-a384-0fcf32210194.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/c2549e10-7f2e-11ea-9f8a-1fe1327e2cd2.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

dashboards/dashboards/caef3ade-d289-4d05-a511-149f3e97f238.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"version": 1,
1919
"timeRestore": false,
2020
"kibanaSavedObjectMeta": {
21-
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\",\"filter\":[]}"
21+
"searchSourceJSON": "{\"highlightAll\":false,\"version\":true,\"query\":{\"language\":\"lucene\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"default_field\":\"*\",\"query\":\"*\"}}},\"filter\":[]}"
2222
}
2323
},
2424
"references": [

0 commit comments

Comments
 (0)