From e090010a69fc764db065b1d7c0da203c0c723eaa Mon Sep 17 00:00:00 2001 From: bpatel Date: Mon, 12 Apr 2021 13:56:26 -0700 Subject: [PATCH] remove ui and app is not visible --- dist/saaws/default/app.conf | 2 +- dist/saaws/default/data/ui/nav/default.xml | 6 - .../default/data/ui/views/escu_summary.xml | 244 ------------------ dist/saaws/default/data/ui/views/feedback.xml | 14 - 4 files changed, 1 insertion(+), 265 deletions(-) delete mode 100644 dist/saaws/default/data/ui/nav/default.xml delete mode 100644 dist/saaws/default/data/ui/views/escu_summary.xml delete mode 100644 dist/saaws/default/data/ui/views/feedback.xml diff --git a/dist/saaws/default/app.conf b/dist/saaws/default/app.conf index b6185cf528..c3cf930f08 100644 --- a/dist/saaws/default/app.conf +++ b/dist/saaws/default/app.conf @@ -23,7 +23,7 @@ version = 3.18.0 description = Explore the Analytic Stories included with Splunk Security Analytics for AWS Content [ui] -is_visible = true +is_visible = false label = Splunk Security Analytics for AWS Content [package] diff --git a/dist/saaws/default/data/ui/nav/default.xml b/dist/saaws/default/data/ui/nav/default.xml deleted file mode 100644 index 234fa77cd9..0000000000 --- a/dist/saaws/default/data/ui/nav/default.xml +++ /dev/null @@ -1,6 +0,0 @@ - diff --git a/dist/saaws/default/data/ui/views/escu_summary.xml b/dist/saaws/default/data/ui/views/escu_summary.xml deleted file mode 100644 index b50088996c..0000000000 --- a/dist/saaws/default/data/ui/views/escu_summary.xml +++ /dev/null @@ -1,244 +0,0 @@ -
- - - - Splunk Security Content - - | rest /services/saved/searches splunk_server=local count=0 | search title="ESCU - *" action.escu.product="*Splunk Security Analytics for AWS*" - - - | rest /services/configs/conf-analytic_stories splunk_server=local count=0 | search product="*Splunk Security Analytics for AWS*" - - - * - * - * - * - - - - -
- - - -

Explore the Analytic Stories included with Splunk Security via ES Use Case Library or Splunk Security Essentials.

- -
-
- - - -
- - - - - - - Total Analytic Stories - - stats count - - - - - - - - - - - - - - - - - - - - Total Detections - - stats count by action.correlationsearch.label| eventstats sum(count) as total_detection_count| fields total_detection_count - - - - - - - - - - - - - - - - - - - - ESCU App Version - - | rest /services/configs/conf-content-version splunk_server=local count=0 | table version - - - - - - - - - - - - - - - - - - - - - Story Categories - - - | rest /services/configs/conf-analytic_stories splunk_server=local count=0 | stats count by category - - - $click.value$ - $click.value$ - - - - - - - - - - - Analytic Stories by MITRE Technique ID - - - - | rest /services/configs/conf-analytic_stories splunk_server=local count=0 - | spath input=mappings path=mitre_attack{} output="MITRE Technique ID" - | stats dc(title) as "Analytic Stories" by "MITRE Technique ID" - - - - $click.value$ - $click.value$ - - - - - - - - - - All - - now - | dedup title | rename title as story | fields story - - story - story - * - " - " - - - - All - - now - rename action.correlationsearch.label as Detection | dedup Detection | fields Detection - - Detection - Detection - " - " - * - - - - All - - now - | dedup category | fields category - - category - category - * - " - " - - - - All - - now - | spath input=mappings path=mitre_attack{} output="MITRE Technique ID" | mvexpand "MITRE Technique ID"| dedup "MITRE Technique ID" | fields "MITRE Technique ID" - - MITRE Technique ID - MITRE Technique ID - " - " - * - - - - All - - now - | spath input=data_models path={} output=dm | mvexpand dm | dedup dm | fields dm - - dm - dm - * - " - " - - - - - - Analytic Story Details - - - spath input=data_models path={} output="Data Models" - | spath input=mappings path=kill_chain_phases{} output="Kill Chain Phases" - | spath input=detection_searches path={} output="Detections" - | spath input=mappings path=mitre_attack{} output="MITRE Technique ID" - | rename title as "Analytic Story" description as "Description" category as "Category" modification_date as "Last Updated" - | fillnull value="-" - | search "Analytic Story"=$as_story$ - | search "Data Models"=$as_data_models$ - | search "Category"=$as_category$ - | search "MITRE Technique ID"=$as_attack_id$ - | search "Detections"=$detection$ - | table "Analytic Story", Description, Category, "MITRE Technique ID", "Data Models", Detections, "Last Updated" - - - - - - - - - - - - -
-
-
- diff --git a/dist/saaws/default/data/ui/views/feedback.xml b/dist/saaws/default/data/ui/views/feedback.xml deleted file mode 100644 index 21de8ed752..0000000000 --- a/dist/saaws/default/data/ui/views/feedback.xml +++ /dev/null @@ -1,14 +0,0 @@ - - - Welcome to Splunk Security Analytics for AWS Content Feedback Center. - - - - Contact us at research@splunk.com to send us support requests, bug reports, or questions directly to the Splunk Security Research Team. -
Please specify your request type and/or the title of any related Analytic Stories.
- You can also find us in the #security-research room in the Splunk Slack channel -
- -
-
-