Skip to content

Commit

Permalink
Winlogbeat Security new dashboards - Older dashboards improvements (e…
Browse files Browse the repository at this point in the history
…lastic#18775)

This PR adds two new dashboards related to events added in PRs (elastic#12906, elastic#14299, elastic#15217, elastic#17517) and implements some improvements to existing winlogbeat security module's dashboard

New Dashboards

    User Logon Dashboard shows all the logon information. It allow us to keep track between logon and admin logons event between RDP connections and disconnections.
    Failed and Blocked Accounts allow us to keep track to failed logons and locked out account

Existing Dashboards

    Added Distribution groups Events (elastic#15217)
    Found that Event 4625 can be generated by two different providers: Microsoft-Windows-Security-Auditing and Microsoft-Windows-EventSystem. Filters to use only the event.code=4625 from Microsoft-Windows-Security-Auditing where added

All Dashboards

    Markdown with links all the winlogbeat security dashboards where added (following the idea of Filebeats, Auditbeat dashboards)
    image

    Visualization that use may events (like group management related visualizations)
    were modified in order to use a saved search with the relevant events for that visualization as a source (instead of using individual filters for each visualization)

    Removed the margin between panels to look in the same way that other beats dashboards

    TSVB metrics were modified to use the Entire Time Range and to use eye-friendlier colors

Co-authored-by: Andrew Kroh <andrew.kroh@elastic.co>
(cherry picked from commit 7b9c535)
  • Loading branch information
janniten authored and andrewkroh committed Nov 16, 2020
1 parent 3d418a7 commit c194dd8
Show file tree
Hide file tree
Showing 10 changed files with 14,042 additions and 7,234 deletions.
1 change: 1 addition & 0 deletions CHANGELOG.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -614,6 +614,7 @@ port. {pull}19209[19209]

*Elastic Log Driver*
- Add support for `docker logs` command {pull}19531[19531]
- Add new winlogbeat security dashboard {pull}18775[18775]

==== Deprecated

Expand Down
Loading

0 comments on commit c194dd8

Please sign in to comment.