Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added new SLA OOB content: #2671

Merged
merged 62 commits into from
Jan 6, 2019
Merged
Show file tree
Hide file tree
Changes from 32 commits
Commits
Show all changes
62 commits
Select commit Hold shift + click to select a range
97b1f1a
Added new SLA OOB content:
Dec 18, 2018
2c3a802
Added new SLA OOB content:
Dec 18, 2018
25c4759
add scheme for sla/grid fields
Dec 19, 2018
94cb8e5
remove unneeded props
Dec 19, 2018
6bc3534
try fix scheme
Dec 19, 2018
6c1f9c7
fix scheme for trigger timers
Dec 19, 2018
a0f323b
Added new SLA OOB content:
Dec 19, 2018
77adbda
Added new SLA OOB content:
Dec 19, 2018
840f2a7
Added new SLA OOB content:
Dec 19, 2018
2a6b44e
Added new SLA OOB content:
Dec 19, 2018
b6327ce
Added new SLA OOB content:
Dec 19, 2018
e7154f8
Added new SLA OOB content:
Dec 19, 2018
cb9122e
new incidentfields file for 4.1 and dashboard field changes
Dec 19, 2018
8b74267
Merge branches 'master' and 'sla-oob-content' of github.com:demisto/c…
Dec 19, 2018
62ddbfe
rollback of incidentfields.json due to creation of a new file for 4.1
Dec 19, 2018
4ff2ad1
deleted unnecessary fromVersion fields
Dec 19, 2018
468321b
added comma
Dec 19, 2018
ec6ac45
added comma
Dec 19, 2018
087c70c
comma?
Dec 19, 2018
2aaa121
comma?
Dec 19, 2018
fcaf6fa
descriptions added AGAIN
Dec 19, 2018
350439c
removed description again
Dec 19, 2018
fa2cf98
add quickview layout
Dec 19, 2018
8a2963c
Fixed descriptions and release notes
Dec 20, 2018
bc86211
Fixed descriptions and release notes
Dec 20, 2018
197292f
Merge branches 'master' and 'sla-oob-content' of github.com:demisto/c…
Dec 23, 2018
7a66de6
Fixed some fields and seperated incidentfield files to 3 different fi…
Dec 23, 2018
0cc6965
tests
Dec 23, 2018
64ac9f2
Added release notes
Dec 23, 2018
aaaab6e
removed dev-prod fields
Dec 24, 2018
7ca78cf
Added phishing investigation playbook file, to support pre-4.1 versions.
idovandijk Dec 25, 2018
09561e8
Merge branch 'master' of github.com:demisto/content into sla-oob-content
idovandijk Dec 25, 2018
d7b094a
Updated fromversion to follow convention. Improved descriptions and e…
idovandijk Dec 26, 2018
4174174
Fixed validation of playbook overlap. Because the old playbook became…
idovandijk Dec 26, 2018
16fb9ac
Merge branches 'master' and 'sla-oob-content' of github.com:demisto/c…
idovandijk Dec 31, 2018
8d8cc0c
Delete script-SendEmailOnSLABreach.yml
glicht Dec 31, 2018
4092ea1
Merge branches 'master' and 'sla-oob-content' of github.com:demisto/c…
idovandijk Jan 1, 2019
eebaa3d
Multiple fixes:
idovandijk Jan 2, 2019
443de5f
Merge branches 'master' and 'sla-oob-content' of github.com:demisto/c…
idovandijk Jan 2, 2019
c064e9c
Multiple fixes:
idovandijk Jan 2, 2019
187c904
Merge branches 'master' and 'sla-oob-content' of github.com:demisto/c…
idovandijk Jan 2, 2019
4845339
Merge branch 'master' of github.com:demisto/content into sla-oob-content
idovandijk Jan 2, 2019
013b798
fixed id_set.json with rony
idovandijk Jan 2, 2019
11abb44
Merge branch 'master' of github.com:demisto/content into sla-oob-content
idovandijk Jan 3, 2019
32686f1
removed CRLFs from id_set.json
idovandijk Jan 3, 2019
def740c
removed CRLFs from id_set.json
idovandijk Jan 3, 2019
e584b5d
removed CRLFs from id_set.json
idovandijk Jan 3, 2019
06202c9
removed CRLFs from id_set.json
idovandijk Jan 3, 2019
f35c34c
removed duplicates from id_set.json
idovandijk Jan 3, 2019
0c35173
Removed another dupe
idovandijk Jan 3, 2019
a928287
Removed more dupes
idovandijk Jan 3, 2019
e2f2f54
Removed more dupes
idovandijk Jan 3, 2019
5aa0300
Removed random spaces at the end of lines
idovandijk Jan 3, 2019
5c5cb8d
Removed random spaces at the end of lines + dupes again
idovandijk Jan 3, 2019
f9d2b21
Added spaces again where needed
idovandijk Jan 3, 2019
43e6bab
what
idovandijk Jan 3, 2019
1053124
still fighting id_set.json
idovandijk Jan 3, 2019
47f2af6
Update id_set.json
idovandijk Jan 3, 2019
c71e5b8
Merge branch 'master' into sla-oob-content
ronykoz Jan 3, 2019
fc62b39
Fixed a bug that would cause remediation timer to stop without being …
idovandijk Jan 6, 2019
a1a9b48
Merge remote-tracking branch 'origin/sla-oob-content' into sla-oob-co…
idovandijk Jan 6, 2019
2d115f5
Merge branch 'master' into sla-oob-content
ronykoz Jan 6, 2019
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
260 changes: 260 additions & 0 deletions Dashboards/dashboard-SLA.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,260 @@
{
"id": "sla-dashboard",
"description": "A new dashboard to give you a good overview of your SLAs.",
"version": -1,
"fromVersion": "4.1.0",
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 7,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z",
"name": "SLA",
"layout": [
{
"id": "25a2e8f0-fd4e-11e8-a656-2b6c8cbabaee",
"forceRange": false,
"x": 6,
"y": 0,
"i": "25a2e8f0-fd4e-11e8-a656-2b6c8cbabaee",
"w": 2,
"h": 1,
"widget": {
"id": "fddd62ff-a411-4e6a-8213-e0277a9b95b5",
"version": 1,
"name": "Mean Time to Detection",
"dataType": "incidents",
"widgetType": "duration",
"query": "-category:job and detectionsla.runStatus:ended",
"sort": null,
"isPredefined": false,
"description": "The mean time (average time) to detection across all incidents that their severity was determined. The widget takes into account incidents from the last 30 days by default.",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 30,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z"
},
"params": {
"keys": [
"avg|detectionsla.totalDuration"
]
},
"size": 0,
"category": ""
}
},
{
"id": "3747f820-fd4e-11e8-a656-2b6c8cbabaee",
"forceRange": false,
"x": 2,
"y": 0,
"i": "3747f820-fd4e-11e8-a656-2b6c8cbabaee",
"w": 2,
"h": 2,
"widget": {
"id": "1e54092d-1ed0-47a6-862d-893adc05e612",
"version": 1,
"name": "Detection SLA by Status",
"dataType": "incidents",
"widgetType": "pie",
"query": "-category:job and -detectionsla.runStatus:idle",
"sort": null,
"isPredefined": false,
"description": "The detection SLA status of all incidents that their severity was determined. The widget takes into account incidents from the last 30 days by default, and inherits new time range when the dashboard time changes.",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 30,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z"
},
"params": {
"groupBy": [
"detectionsla.slaStatus"
]
},
"size": 0,
"category": ""
}
},
{
"id": "3de5b1e0-fd4e-11e8-a656-2b6c8cbabaee",
"forceRange": false,
"x": 4,
"y": 0,
"i": "3de5b1e0-fd4e-11e8-a656-2b6c8cbabaee",
"w": 2,
"h": 2,
"widget": {
"id": "1767dee0-7f8c-48a5-8988-c58b9e713ab6",
"version": 1,
"name": "Remediation SLA by Status",
"dataType": "incidents",
"widgetType": "pie",
"query": "-category:job and -remediationsla.runStatus:idle",
"sort": null,
"isPredefined": false,
"description": "The remediation SLA status of all incidents that started a remediation process. The widget takes into account incidents from the last 30 days by default, and inherits new time range when the dashboard time changes.",
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 30,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z"
},
"params": {
"groupBy": [
"remediationsla.slaStatus"
]
},
"size": 0,
"category": ""
}
},
{
"id": "a48c1670-fdf1-11e8-a2fa-df5e7de7d45d",
"forceRange": false,
"x": 8,
"y": 0,
"i": "a48c1670-fdf1-11e8-a2fa-df5e7de7d45d",
"w": 2,
"h": 1,
"widget": {
"id": "mean-time-to-resolution",
"version": 169,
"name": "Mean Time To Resolution",
"dataType": "incidents",
"widgetType": "duration",
"query": "-category:job and status:closed",
"sort": null,
"isPredefined": true,
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 7,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z"
},
"params": {
"keys": [
"avg|openDuration",
"count|1"
]
},
"size": 0,
"category": ""
}
},
{
"id": "d2bbe430-02a1-11e9-878d-4fff182656eb",
"forceRange": false,
"x": 2,
"y": 2,
"i": "d2bbe430-02a1-11e9-878d-4fff182656eb",
"w": 4,
"h": 2,
"widget": {
"id": "mttd-by-type",
"version": 1,
"name": "MTTD by Type",
"dataType": "incidents",
"widgetType": "line",
"query": "-category:job and detectionsla.runStatus:ended",
"sort": null,
"isPredefined": false,
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 7,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z"
},
"params": {
"groupBy": [
"occurred(d)",
"type"
],
"keys": [
"avg|detectionsla.totalDuration / 60"
]
},
"size": 0,
"category": ""
}
},
{
"id": "e30f9430-02a1-11e9-878d-4fff182656eb",
"forceRange": false,
"x": 6,
"y": 1,
"i": "e30f9430-02a1-11e9-878d-4fff182656eb",
"w": 4,
"h": 3,
"widget": {
"id": "mttr-by-type",
"version": 168,
"name": "MTTR by Type",
"dataType": "incidents",
"widgetType": "line",
"query": "-category:job and status:closed",
"sort": null,
"isPredefined": true,
"dateRange": {
"fromDate": "0001-01-01T00:00:00Z",
"toDate": "0001-01-01T00:00:00Z",
"period": {
"byTo": "",
"byFrom": "days",
"toValue": null,
"fromValue": 7,
"field": ""
},
"fromDateLicense": "0001-01-01T00:00:00Z"
},
"params": {
"groupBy": [
"occurred(d)",
"type"
],
"keys": [
"avg|openDuration / (3600*24)"
]
},
"size": 0,
"category": ""
}
}
],
"isPredefined": false
}
37 changes: 37 additions & 0 deletions IncidentFields/incidentfield-detectionsla.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{
"closeForm": false,
"cliName": "detectionsla",
"fromVersion": "4.1.0",
"neverSetAsRequired": false,
"threshold": 72,
"id": "incident_detectionsla",
"group": 0,
"script": "",
"isReadOnly": true,
"system": false,
"content": true,
"unsearchable": false,
"version": -1,
"unmapped": false,
"hidden": false,
"type": "timer",
"editForm": false,
"description": "The time it took from incident creation until the maliciousness was determined.",
"associatedToAll": true,
"breachScript": "",
"associatedTypes": [],
"caseInsensitive": true,
"placeholder": "",
"useAsKpi": true,
"systemAssociatedTypes": null,
"locked": false,
"name": "Detection SLA",
"ownerOnly": false,
"required": false,
"modified": "2018-12-11T12:53:48.369705659Z",
"fieldCalcScript": "",
"selectValues": [],
"validationRegex": "",
"sla": 20,
"releaseNotes": "Added Detection SLA field"
}
37 changes: 37 additions & 0 deletions IncidentFields/incidentfield-remediationsla.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{
"closeForm": false,
"fromVersion": "4.1.0",
"cliName": "remediationsla",
"neverSetAsRequired": false,
"threshold": 72,
"id": "incident_remediationsla",
"group": 0,
"script": "",
"isReadOnly": true,
"system": false,
"content": true,
"unsearchable": false,
"version": -1,
"unmapped": false,
"hidden": false,
"type": "timer",
"editForm": false,
"description": "The time it took since remediation of the incident began, and until it ended.",
"associatedToAll": true,
"breachScript": "",
"associatedTypes": [],
"caseInsensitive": true,
"placeholder": "",
"useAsKpi": true,
"systemAssociatedTypes": null,
"locked": false,
"name": "Remediation SLA",
"ownerOnly": false,
"required": false,
"modified": "2018-12-11T12:53:56.816268002Z",
"fieldCalcScript": "",
"selectValues": [],
"validationRegex": "",
"sla": 7200,
"releaseNotes": "Added Remediation SLA field"
}
37 changes: 37 additions & 0 deletions IncidentFields/incidentfield-timetoassignment.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{
"closeForm": false,
"cliName": "timetoassignment",
"fromVersion": "4.1.0",
"neverSetAsRequired": false,
"threshold": 72,
"id": "incident_timetoassignment",
"group": 0,
"script": "",
"isReadOnly": true,
"system": false,
"content": true,
"unsearchable": false,
"version": -1,
"unmapped": false,
"hidden": false,
"type": "timer",
"editForm": false,
"description": "The time it took from when the incident was created until a user was assigned to it.",
"associatedToAll": true,
"breachScript": "",
"associatedTypes": null,
"caseInsensitive": true,
"placeholder": "",
"useAsKpi": true,
"systemAssociatedTypes": null,
"locked": false,
"name": "Time to Assignment",
"ownerOnly": false,
"required": false,
"modified": "2018-12-11T12:55:38.305896432Z",
"fieldCalcScript": "",
"selectValues": null,
"validationRegex": "",
"sla": 0,
"releaseNotes": "Added Time to Assignment field"
}
2 changes: 1 addition & 1 deletion IncidentFields/incidentfields.json
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
{
"releaseNotes": "-",
"incidentFields": [
{
"id": "incident_app",
Expand Down Expand Up @@ -1653,4 +1654,3 @@
}
]
}

Loading