Skip to content

Commit 6f39b2d

Browse files
committed
Proposed fixes for issue #1 & #2
1 parent 18abb88 commit 6f39b2d

File tree

1 file changed

+12
-9
lines changed

1 file changed

+12
-9
lines changed

default/data/ui/views/attack_range_main_dashboard.xml

Lines changed: 12 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -250,6 +250,7 @@
250250
<row>
251251
<panel>
252252
<title>Potential Analytic stories [$story_count$]</title>
253+
<html><span><b>Note:</b> The &quot;View [ES]&quot; links will ony work if you have Splunk Eterprise Security installed as part of Attack Range.</span></html>
253254
<table>
254255
<search>
255256
<progress>
@@ -289,10 +290,10 @@
289290
<option name="wrap">true</option>
290291
<drilldown>
291292
<condition field="view">
292-
<link target="_blank">/app/DA-ESS-ContentUpdate/analytic_story_details?form.analytic_story_name=$click.value$</link>
293+
<link target="_blank">/app/SplunkEnterpriseSecuritySuite/ess_analytic_story_details?analytic_story=$click.value$</link>
293294
</condition>
294295
<condition field="title">
295-
<link target="_blank">/app/DA-ESS-ContentUpdate/analytic_story_details?form.analytic_story_name=$click.value$</link>
296+
<link target="_blank">/app/SplunkEnterpriseSecuritySuite/ess_analytic_story_details?analytic_story=$click.value$</link>
296297
</condition>
297298
<condition field="execute">
298299
<link target="_blank">/app/Splunk_ASX/execute?form.mode=now&amp;form.time.earliest=-24h@h&amp;form.time.latest=now&amp;form.story=$row.title$</link>
@@ -308,14 +309,16 @@
308309
<set token="detection_count">$job.resultCount$</set>
309310
</progress>
310311
<query>`get_attack_data`
311-
|rename Technique as mitre_technique
312-
312+
| rename Technique as mitre_technique
313313
| join type=left max=0 mitre_technique
314-
[| sseanalytics
315-
|search mitre_technique!="None"
316-
|mvexpand mitre_technique]
317-
|stats dc(name) by name,mitre_technique,channel
318-
|table name, mitre_technique, channel</query>
314+
[
315+
| sseanalytics
316+
| search mitre_id!="None"
317+
| mvexpand mitre_id
318+
| rename mitre_id as mitre_technique
319+
]
320+
| stats dc(name) by name,mitre_technique,channel
321+
| table name, mitre_technique, channel</query>
319322
<earliest>$time_token.earliest$</earliest>
320323
<latest>$time_token.latest$</latest>
321324
<sampleRatio>1</sampleRatio>

0 commit comments

Comments
 (0)