THIS IS A TEST INSTANCE. ALL YOUR CHANGES WILL BE LOST!!!!
...
- Log into the Metron UI Dashboard: http://METRON_UI_HOST:5000.
- Select "Discover" Tab --> Select the "squid*" index.
- Search only for alerts in the Squid index.
- Type the following in search:
"is_alert = true" - Click the search icon
- Type the following in search:
- Now we only need to select a subset of the fields that we want to display in the detail panel. In the left hand panel under "Available Fields", add the following fields:
full_hostname
ip_src_addr
ip_dst_addr
original_string
method
type
Dashboard with the Two Panels
...