Skip to content

Commit

Permalink
Improve performance of PANW module dashboards (elastic#19032)
Browse files Browse the repository at this point in the history
A saved search was using `panw.panos: *` as to filter for data from the
dataset, instead of the more efficient `event.dataset: panw.panos`.
  • Loading branch information
adriansr authored Jun 9, 2020
1 parent af4ebe5 commit 2dad8db
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 3 deletions.
2 changes: 1 addition & 1 deletion CHANGELOG.next.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -378,7 +378,7 @@ https://github.com/elastic/beats/compare/v7.0.0-alpha2...master[Check the HEAD d
- Improve ECS categorization field mappings in cisco module. {issue}16028[16028] {pull}18537[18537]
- The s3 input can now automatically detect gzipped objects. {issue}18283[18283] {pull}18764[18764]
- Add geoip AS lookup & improve ECS categorization in aws cloudtrail fileset. {issue}18644[18644] {pull}18958[18958]

- Improved performance of PANW sample dashboards. {issue}19031[19031] {pull}19032[19032]

*Heartbeat*

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1075,7 +1075,7 @@
"indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.index",
"query": {
"language": "kuery",
"query": "panw.panos:* and event.category: \"network_traffic\""
"query": "event.dataset: \"panw.panos\" and event.category: \"network_traffic\""
},
"version": true
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -764,7 +764,7 @@
"indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.index",
"query": {
"language": "kuery",
"query": "panw.panos:* and event.category: \"security_threat\""
"query": "event.dataset: \"panw.panos\" and event.category: \"security_threat\""
},
"version": true
}
Expand Down

0 comments on commit 2dad8db

Please sign in to comment.