Skip to content

Commit 4087f28

Browse files
committed
Added macro for attack data query
1 parent ef4a846 commit 4087f28

File tree

3 files changed

+13
-3
lines changed

3 files changed

+13
-3
lines changed

local/data/ui/views/attack_range_main_dashboard.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
<form theme="dark">
22
<search id="BaseSearch">
3-
<query>index="attack" Technique!="Technique" Technique!=""
3+
<query>`get_attack_data`
44
| sseidenrichment type=mitreid field=Technique
55
| eval mitre_id = Technique+" - "+mitre_technique_display, atomic_test= 'Test Number'+"-"+'Test Name'
66
|lookup mitre_matrix_list_ar Technique AS mitre_technique_display
@@ -234,7 +234,7 @@
234234
<title>Possible Analytic stories</title>
235235
<table>
236236
<search>
237-
<query>index="attack" Technique!="Technique"
237+
<query>`get_attack_data`
238238
| sseidenrichment type=mitreid field=Technique
239239
| eval mitre_id = Technique+" - "+mitre_technique_display, atomic_test= 'Test Number'+"-"+'Test Name'
240240
|lookup mitre_matrix_list_ar Technique AS mitre_technique_display

local/macros.conf

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
[get_attack_data]
2+
definition = index="attack" Technique!="Technique" Technique!="" Technique!="T1531"
3+
iseval = 0

metadata/local.meta

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ access = read : [ * ]
1111
export = none
1212
owner = admin
1313
version = 8.0.1
14-
modtime = 1586941209.657182000
14+
modtime = 1587039557.989469000
1515

1616
[views/attack_range_navigator]
1717
access = read : [ * ]
@@ -55,3 +55,10 @@ export = none
5555
owner = admin
5656
version = 8.0.1
5757
modtime = 1586924042.816955000
58+
59+
[macros/get_attack_data]
60+
access = read : [ * ]
61+
export = none
62+
owner = admin
63+
version = 8.0.1
64+
modtime = 1587039526.751615000

0 commit comments

Comments
 (0)