{
  "version": "Notebook/1.0",
  "items": [
    {
      "type": 1,
      "content": {
        "json": ">**NOTE:** This workbook depends on a parser based on a Kusto Function to work as expected [**Corelight**](https://aka.ms/sentinel-Corelight-parser) which is deployed with the Microsoft Sentinel Solution."
      },
      "name": "text - 23"
    },
    {
      "type": 9,
      "content": {
        "version": "KqlParameterItem/1.0",
        "parameters": [
          {
            "id": "c64d5d3d-90c6-484a-ab88-c70652b75b6e",
            "version": "KqlParameterItem/1.0",
            "name": "GlobalTimeRestriction",
            "label": "Global Time Restriction",
            "type": 4,
            "description": "Select Time Range",
            "isRequired": true,
            "typeSettings": {
              "selectableValues": [
                {
                  "durationMs": 300000
                },
                {
                  "durationMs": 900000
                },
                {
                  "durationMs": 1800000
                },
                {
                  "durationMs": 3600000
                },
                {
                  "durationMs": 14400000
                },
                {
                  "durationMs": 43200000
                },
                {
                  "durationMs": 86400000
                },
                {
                  "durationMs": 172800000
                },
                {
                  "durationMs": 259200000
                },
                {
                  "durationMs": 604800000
                },
                {
                  "durationMs": 1209600000
                },
                {
                  "durationMs": 2419200000
                },
                {
                  "durationMs": 2592000000
                },
                {
                  "durationMs": 5184000000
                },
                {
                  "durationMs": 7776000000
                }
              ],
              "allowCustom": true
            },
            "timeContext": {
              "durationMs": 86400000
            },
            "value": {
              "durationMs": 86400000
            }
          },
          {
            "id": "a076210e-a47c-43c2-97e1-1f663fedbd01",
            "version": "KqlParameterItem/1.0",
            "name": "Sensor",
            "label": "Corelight Sensor",
            "type": 2,
            "description": "Select Corelight Sensor",
            "isRequired": true,
            "multiSelect": true,
            "quote": "'",
            "delimiter": ",",
            "query": "corelight_conn\n| distinct sensor_name\n| sort by sensor_name",
            "typeSettings": {
              "additionalResourceOptions": [
                "value::all"
              ],
              "selectAllValue": "*",
              "showDefault": false
            },
            "timeContext": {
              "durationMs": 0
            },
            "timeContextFromParameter": "GlobalTimeRestriction",
            "defaultValue": "value::all",
            "queryType": 0,
            "resourceType": "microsoft.operationalinsights/workspaces"
          }
        ],
        "style": "pills",
        "queryType": 0,
        "resourceType": "microsoft.operationalinsights/workspaces"
      },
      "name": "parameters - 1"
    },
    {
      "type": 12,
      "content": {
        "version": "NotebookGroup/1.0",
        "groupType": "editable",
        "items": [
          {
            "type": 11,
            "content": {
              "version": "LinkItem/1.0",
              "style": "tabs",
              "links": [
                {
                  "id": "5736d4f4-bd4c-4a49-bea7-00da2bbc7fd9",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "Connections",
                  "subTarget": "corelight_connections",
                  "style": "link"
                },
                {
                  "id": "5336f601-4da3-4da0-8196-332a97636047",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "DNS",
                  "subTarget": "corelight_dns",
                  "style": "link"
                },
                {
                  "id": "c298ad2a-ee5f-4fb2-8c09-ff8d867926d0",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "Files",
                  "subTarget": "corelight_files",
                  "style": "link"
                },
                {
                  "id": "b0e6ac55-179e-4fb5-80ff-ec84edb35324",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "HTTP",
                  "subTarget": "corelight_http",
                  "style": "link"
                },
                {
                  "id": "7aafc143-f7f6-4942-9c87-a14956eed4b8",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "Software",
                  "subTarget": "corelight_software",
                  "style": "link"
                },
                {
                  "id": "713f8a7a-769b-4c9c-9f55-bceafce20d63",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "SSL and x509",
                  "subTarget": "corelight_ssl_x509",
                  "style": "link"
                },
                {
                  "id": "d126c0d3-1ad5-430c-8cdb-95ab387c464a",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "AWS VPC Flow",
                  "subTarget": "aws_vpc_flow",
                  "style": "link"
                },
                {
                  "id": "3b67f023-6b39-46de-9bba-a72970b6f6f3",
                  "cellValue": "Tab",
                  "linkTarget": "parameter",
                  "linkLabel": "Asset Classification",
                  "subTarget": "asset_classification",
                  "style": "link"
                }
              ]
            },
            "name": "links - 24"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "eb78de55-e30a-4e11-b1df-a94987f625b5",
                        "version": "KqlParameterItem/1.0",
                        "name": "id_orig_h",
                        "label": "Originator IP (src_ip)",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "da839a01-802a-448d-ba4f-28c1a5bbfe72",
                        "version": "KqlParameterItem/1.0",
                        "name": "id_orig_p",
                        "label": "Originator Port (src_port)",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "b9c1f005-4e91-4aa0-8842-8fc60f4b4068",
                        "version": "KqlParameterItem/1.0",
                        "name": "id_resp_h",
                        "label": "Responder IP (dest_ip)",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "a0807d9b-0e96-4bbf-a689-759af75e1f6e",
                        "version": "KqlParameterItem/1.0",
                        "name": "id_resp_p",
                        "label": "Responder Port (dest_port)",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "c4c74606-9f17-41f0-9b76-c8bf4ed934b9",
                        "version": "KqlParameterItem/1.0",
                        "name": "ShowAggregation",
                        "label": "Show Aggregation",
                        "type": 2,
                        "isRequired": true,
                        "typeSettings": {
                          "showDefault": false
                        },
                        "jsonData": "[\"Yes\", \"No\"]",
                        "value": "No"
                      },
                      {
                        "id": "e1c12e0b-0157-4eb2-90c8-7890827de86d",
                        "version": "KqlParameterItem/1.0",
                        "name": "service",
                        "label": "Service",
                        "type": 2,
                        "isRequired": true,
                        "query": "let pre_services = datatable(service: string) [\r\n    \"dce_rpc\",\r\n    \"dhcp\",\r\n    \"dns\",\r\n    \"ftp\",\r\n    \"gssapi,smb,krb\",\r\n    \"http\",\r\n    \"krb_tcp\",\r\n    \"ntp\",\r\n    \"smb\",\r\n    \"smb,gssapi,ntlm\",\r\n    \"smb,ntlm,gssapi\",\r\n    \"smtp\",\r\n    \"ssh\",\r\n    \"ssl\",\r\n    \"xmpp,ssl\",\r\n    \"vxlan\",\r\n    \"dce_rpc,gssapi,ntlm,smb\",\r\n    \"dce_rpc,smb\",\r\n    \"dnp3_tcp\",\r\n    \"ftp-data\",\r\n    \"gssapi\",\r\n    \"gssapi,ntlm,smb\",\r\n    \"gssapi,smb\",\r\n    \"http,socks\",\r\n    \"imap\",\r\n    \"irc\",\r\n    \"irc-dcc-data\",\r\n    \"mqtt\",\r\n    \"rdp\",\r\n    \"smb,gssapi\",\r\n    \"socks\",\r\n    \"ssl,ftp\",\r\n    \"ssl,socks\",\r\n    \"ssl,xmpp\",\r\n    \"xmpp\",\r\n    \"ftp,ssl\",\r\n    \"ntlm,gssapi,smb\",\r\n    \"ntlm,gssapi,smb,dce_rpc\",\r\n    \"smb,dce_rpc\",\r\n    \"socks,http\",\r\n    \"ssl,smtp\",\r\n    \"bacnet\",\r\n    \"ntlm,smb,gssapi\",\r\n    \"smtp,ssl\",\r\n    \"gssapi,smb,ntlm\",\r\n    \"gssapi,dce_rpc,ntlm,smb\",\r\n    \"smb,dce_rpc,gssapi,ntlm\",\r\n    \"socks,ssl\",\r\n    \"ntlm,dce_rpc,gssapi,smb\",\r\n    \"ntlm,dce_rpc,smb,gssapi\",\r\n    \"gssapi,ntlm,dce_rpc,smb\",\r\n    \"smtp/ssl\",\r\n    \"xmpp/ssl\"\r\n];\r\n\r\nunion\r\n    (corelight_conn_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_conn\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| project app \r\n| where isnotempty(app)\r\n| mv-expand service = app\r\n| distinct tostring(service)\r\n| sort by tostring(service) asc\r\n| union pre_services\r\n",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": "value::all"
                      },
                      {
                        "id": "a6972852-6429-4fe8-822a-1b7abe1aa9f4",
                        "version": "KqlParameterItem/1.0",
                        "name": "AdditionalFilter",
                        "label": "Additional Filter",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "f991d796-7228-4e02-880c-13283d3e5884",
                        "version": "KqlParameterItem/1.0",
                        "name": "connection_uid",
                        "label": "Connection UID",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters - 1 - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n    and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| extend total_bytes = bytes_in + bytes_out\n| summarize volume = sum(total_bytes)",
                    "size": 3,
                    "title": "Traffic Volume",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "titleContent": {
                        "columnMatch": "formatted_volume",
                        "formatter": 1
                      },
                      "leftContent": {
                        "columnMatch": "volume",
                        "formatter": 12,
                        "formatOptions": {
                          "palette": "auto"
                        },
                        "numberFormat": {
                          "unit": 2,
                          "options": {
                            "style": "decimal",
                            "maximumFractionDigits": 2,
                            "maximumSignificantDigits": 3
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "20",
                  "name": "query - 14"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| summarize dc_src = dcount(src)\n",
                    "size": 3,
                    "title": "Traffic Sources",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "titleContent": {
                        "columnMatch": "dc_src_fmt",
                        "formatter": 0
                      },
                      "leftContent": {
                        "columnMatch": "dc_src",
                        "formatter": 12,
                        "formatOptions": {
                          "palette": "auto"
                        },
                        "numberFormat": {
                          "unit": 17,
                          "options": {
                            "style": "decimal",
                            "maximumFractionDigits": 2,
                            "maximumSignificantDigits": 3
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "20",
                  "name": "query - 14 - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| summarize dc_session_id = dcount(session_id)\n",
                    "size": 3,
                    "title": "Traffic Connections",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "titleContent": {
                        "columnMatch": "dc_session_id_fmt",
                        "formatter": 1
                      },
                      "leftContent": {
                        "columnMatch": "dc_session_id",
                        "formatter": 12,
                        "formatOptions": {
                          "palette": "auto"
                        },
                        "numberFormat": {
                          "unit": 17,
                          "options": {
                            "style": "decimal",
                            "maximumFractionDigits": 2,
                            "maximumSignificantDigits": 3
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "20",
                  "name": "query - 14 - Copy - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| summarize dc_dest = dcount(dest)",
                    "size": 3,
                    "title": "Traffic Destinations",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "titleContent": {
                        "columnMatch": "dc_dest_fmt",
                        "formatter": 1
                      },
                      "leftContent": {
                        "columnMatch": "dc_dest",
                        "formatter": 12,
                        "formatOptions": {
                          "palette": "auto"
                        },
                        "numberFormat": {
                          "unit": 17,
                          "options": {
                            "style": "decimal",
                            "maximumFractionDigits": 2,
                            "maximumSignificantDigits": 3
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "20",
                  "name": "query - 14 - Copy - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "corelight_conn_agg\n| count\n| extend\n    status_text = iff(Count > 0, \"Conn Agg Logs Available\", \"No Conn Agg Logs\")\n| project status_text\n",
                    "size": 3,
                    "title": "Conn Aggregation (Last 1 Hour)",
                    "timeContext": {
                      "durationMs": 3600000
                    },
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "titleContent": {
                        "columnMatch": "text_",
                        "formatter": 1
                      },
                      "leftContent": {
                        "columnMatch": "status_text",
                        "formatter": 1
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "20",
                  "name": "query - 14 - Copy - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| where not(is_broadcast == \"true\" and local_resp == \"true\") \n| search '{AdditionalFilter}'\n| mv-expand service = app\n| where ('*' == ('{service}') or service == ('{service}'))\n| extend service = coalesce(service, \"unknown\")\n| summarize Count = count() by service\n| top 10 by Count",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Top Services",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "series",
                    "exportParameterName": "service_top",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "piechart",
                    "chartSettings": {
                      "createOtherGroup": 10
                    }
                  },
                  "customWidth": "50",
                  "name": "top_responder_ports"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| where not(is_broadcast == \"true\" and local_resp == \"true\")\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| extend id_resp_p = toint(id_resp_p)\n| extend id_resp_p = coalesce(tostring(id_resp_p), \"unknown\")\n| summarize Count = count() by tostring(id_resp_p)\n| top 10 by Count\n",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Top Responder Ports",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "series",
                    "exportParameterName": "id_resp_p_top",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "piechart",
                    "chartSettings": {
                      "createOtherGroup": 10
                    }
                  },
                  "customWidth": "50",
                  "name": "top_responder_ports"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the sections in the above panel **Top Services** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 1"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the sections in the above panel **Top Responder Ports** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 1"
                      }
                    ]
                  },
                  "name": "group - 12"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_conn_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_conn\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \r\n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\r\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\r\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\r\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\r\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\r\n| where not(is_broadcast == \"true\" and local_resp == \"true\")\r\n| mv-expand service = app\r\n| extend service = coalesce(service, \"unknown\")\r\n| where service == ('{service_top}')\r\n| search '{AdditionalFilter}'\r\n| extend tunnel_parents = strcat_array(todynamic(tunnel_parents), \", \"), suri_ids = strcat_array(todynamic(suri_ids), \", \"), apps = strcat_array(todynamic(apps), \", \"), id_orig_h_n_vals = strcat_array(todynamic(id_orig_h_n_vals), \", \"),\r\n         id_resp_h_n_vals = strcat_array(todynamic(id_resp_h_n_vals), \", \")\r\n| project-away $table",
                    "size": 0,
                    "showAnalytics": true,
                    "title": " Details of Service: {service_top}",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "service_top",
                    "comparison": "isNotEqualTo"
                  },
                  "name": "query - 1",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_conn_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_conn\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \r\n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\r\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\r\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\r\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\r\n| where not(is_broadcast == \"true\" and local_resp == \"true\")\r\n| search '{AdditionalFilter}'\r\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\r\n| extend id_resp_p = toint(id_resp_p)\r\n| extend id_resp_p = coalesce(tostring(id_resp_p), \"unknown\")\r\n| where tostring(id_resp_p) == ('{id_resp_p_top}')\r\n| extend tunnel_parents = strcat_array(todynamic(tunnel_parents), \", \"), suri_ids = strcat_array(todynamic(suri_ids), \", \"), apps = strcat_array(todynamic(apps), \", \"),\r\n         app = strcat_array(app, \", \"), id_orig_h_n_vals = strcat_array(todynamic(id_orig_h_n_vals), \", \"),\r\n         id_resp_h_n_vals = strcat_array(todynamic(id_resp_h_n_vals), \", \")\r\n| project-away $table",
                    "size": 0,
                    "showAnalytics": true,
                    "title": " Details of Responder Port: {id_resp_p_top}",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "id_resp_p_top",
                    "comparison": "isNotEqualTo"
                  },
                  "name": "query - 1",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| where not(is_broadcast == \"true\" and local_resp == \"true\")\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| extend id_orig_h = coalesce(id_orig_h, \"unknown\")\n| summarize Count = count() by tostring (id_orig_h)\n| top 10 by Count",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Top Originators (sources) by # of connections ",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "series",
                    "exportParameterName": "id_orig_h_top",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "piechart",
                    "chartSettings": {
                      "createOtherGroup": 10
                    }
                  },
                  "customWidth": "50",
                  "name": "top_responder_ports"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| where not(is_broadcast == \"true\" and local_resp == \"true\") \n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| extend id_resp_h = coalesce(id_resp_h, \"unknown\")\n| summarize Count = count() by tostring (id_resp_h)\n| top 10 by Count\n",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Top Responders (destinations) by # of connections",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "series",
                    "exportParameterName": "id_resp_h_top",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "piechart",
                    "chartSettings": {
                      "createOtherGroup": 10
                    }
                  },
                  "customWidth": "50",
                  "name": "top_responder_ports"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the sections in the above panel **Top Originators (sources) by # of connections** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 1"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the sections in the above panel **Top Responders (destinations) by # of connections ** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 1"
                      }
                    ]
                  },
                  "name": "group - 13"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_conn_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_conn\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \r\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\r\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\r\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\r\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\r\n| where not(is_broadcast == \"true\" and local_resp == \"true\")\r\n| search '{AdditionalFilter}'\r\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\r\n| extend id_orig_h = coalesce(id_orig_h, \"unknown\")\r\n| where id_orig_h == ('{id_orig_h_top}')\r\n| extend tunnel_parents = strcat_array(todynamic(tunnel_parents), \", \"), suri_ids = strcat_array(todynamic(suri_ids), \", \"), apps = strcat_array(todynamic(apps), \", \"),\r\n         app = strcat_array(app, \", \"), id_orig_h_n_vals = strcat_array(todynamic(id_orig_h_n_vals), \", \"),\r\n         id_resp_h_n_vals = strcat_array(todynamic(id_resp_h_n_vals), \", \")\r\n| project-away $table",
                    "size": 0,
                    "showAnalytics": true,
                    "title": " Details of Source: {id_orig_h_top}",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "id_orig_h_top",
                    "comparison": "isNotEqualTo"
                  },
                  "name": "query - 1",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_conn_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_conn\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \r\n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\r\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\r\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\r\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\r\n| where not(is_broadcast == \"true\" and local_resp == \"true\")\r\n| search '{AdditionalFilter}'\r\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\r\n| extend id_resp_h = coalesce(id_resp_h, \"unknown\")\r\n| where id_resp_h == ('{id_resp_h_top}')\r\n| extend tunnel_parents = strcat_array(todynamic(tunnel_parents), \", \"), suri_ids = strcat_array(todynamic(suri_ids), \", \"), apps = strcat_array(todynamic(apps), \", \"),\r\n         app = strcat_array(app, \", \"), id_orig_h_n_vals = strcat_array(todynamic(id_orig_h_n_vals), \", \"),\r\n         id_resp_h_n_vals = strcat_array(todynamic(id_resp_h_n_vals), \", \")\r\n| project-away $table",
                    "size": 0,
                    "showAnalytics": true,
                    "title": " Details of Destination: {id_resp_h_top}",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "id_resp_h_top",
                    "comparison": "isNotEqualTo"
                  },
                  "name": "query - 1",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| where not(is_broadcast == \"true\" and local_resp == \"true\") \n       and direction == \"outbound\"\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| summarize  Service = make_set(app), Bytes = sum(orig_ip_bytes) by id_orig_h, id_resp_h\n| top 10 by Bytes\n| extend ipinfo = geo_info_from_ip_address(id_resp_h)\n| extend Country = tostring(ipinfo.country)\n| extend Service = strcat_array(Service, \", \")\n| project [\"Source IP\"] = id_orig_h, [\"Destination IP\"] = id_resp_h, Country, Bytes, Service",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top Outbound Data Flows by Originator (src_ip) Bytes",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Bytes",
                          "formatter": 0,
                          "formatOptions": {
                            "aggregation": "Count"
                          },
                          "numberFormat": {
                            "unit": 36,
                            "options": {
                              "style": "decimal"
                            }
                          }
                        }
                      ],
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "50",
                  "name": "top_outbound_bytes",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_conn\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) \n       and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n       and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n       and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n       and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n       and (('*' == ('{connection_uid}') or uid contains ('{connection_uid}')) )\n| where not(is_broadcast == \"true\" and local_resp == \"true\") \n       and direction == \"inbound\"\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| summarize  service = make_set(app), Bytes = sum(orig_ip_bytes) by id_orig_h, id_resp_h\n| top 10 by Bytes\n| extend ipinfo = geo_info_from_ip_address(id_orig_h)\n| extend Country = tostring(ipinfo.country)\n| extend Service = strcat_array(service, \", \")\n| project [\"Source IP\"] = id_orig_h, [\"Destination IP\"] = id_resp_h, Country, Bytes, Service",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top Inbound Data Flows by Originator (src_ip) Bytes",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Bytes",
                          "formatter": 0,
                          "formatOptions": {
                            "aggregation": "Count"
                          },
                          "numberFormat": {
                            "unit": 36,
                            "options": {
                              "style": "decimal"
                            }
                          }
                        }
                      ],
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "50",
                  "name": "top_inbound_by_orig",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n(\n    corelight_conn_agg\n    | where '{ShowAggregation}' == \"Yes\"\n),\n(\n    corelight_conn\n    | where '{ShowAggregation}' == \"No\"\n)\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n    and (('*' == ('{id_orig_h}') or id_orig_h == ('{id_orig_h}')) )\n    and (('*' == ('{id_orig_p}') or id_orig_p == ('{id_orig_p}')) )\n    and (('*' == ('{id_resp_h}') or id_resp_h == ('{id_resp_h}')) )\n    and (('*' == ('{id_resp_p}') or id_resp_p == ('{id_resp_p}')) )\n    and ('*' == '{connection_uid}' or uid contains '{connection_uid}')\n| where not(is_broadcast == \"true\" and local_resp == \"true\") \n    and isnotempty(uid)\n| search '{AdditionalFilter}'\n| where ('*' == ('{service}') or set_has_element(app, '{service}'))\n| summarize\n    duration = avg(duration),\n    src_ip = make_set(id_orig_h),\n    dest_ip = make_set(id_resp_h),\n    dest_port = make_set(id_resp_p),\n    service = make_set(app)\n    by session_id = uid\n| extend duration = duration / 1000.0\n| sort by duration desc\n| take 100\n| project UID = session_id, Duration = duration, [\"Source IP\"] = src_ip, [\"Destination IP\"] = dest_ip, [\"Destination Port\"]=dest_port, Service = service\n",
                          "size": 2,
                          "showAnalytics": true,
                          "title": "Top 100 Open/Active Long Lived Connections (Requires Long Connections Pkg)",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "UID",
                          "exportParameterName": "open_uid",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 100,
                            "filter": true
                          },
                          "chartSettings": {
                            "createOtherGroup": 10,
                            "showMetrics": false,
                            "showLegend": true
                          }
                        },
                        "name": "top_responder_ports",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **Top 100 Open/Active Long Lived Connections (Requires Long Connections Pkg)** to view more information.",
                          "style": "info"
                        },
                        "name": "text - 1"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let dummy_table = datatable(uid: string, TenantId: string, SourceSystem: string, MG: string, ManagementGroupName: string, Computer: string, RawData: string, _ResourceId: string)[];\r\n\r\nunion Corelight*, dummy_table\r\n| where uid == '{open_uid}' or uids == '{open_uid}'\r\n| project-away TenantId, SourceSystem, MG, ManagementGroupName, Computer, RawData, _ResourceId",
                          "size": 0,
                          "showAnalytics": true,
                          "title": " Details of UID: {open_uid}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "open_uid",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 1",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "name": "group - 15 - Copy - Copy - Copy - Copy"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "corelight_connections"
            },
            "name": "corelight_connections_group"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "f34f11b1-97e8-45cc-85ed-010931083a1b",
                        "version": "KqlParameterItem/1.0",
                        "name": "ShowAggregation",
                        "label": "Show Aggregation",
                        "type": 2,
                        "isRequired": true,
                        "jsonData": "[\"Yes\", \"No\"]",
                        "value": "No"
                      },
                      {
                        "id": "2c572253-ce24-4ebd-add0-ec4ce0b07d7c",
                        "version": "KqlParameterItem/1.0",
                        "name": "ResponderPort",
                        "label": "Responder Port (dest_port)",
                        "type": 2,
                        "description": "Select Responder Port",
                        "isRequired": true,
                        "query": "let DNSPorts = datatable(\r\n        id_resp_p: int\r\n    )[\r\n        137,\r\n        53,\r\n        5353,\r\n        5355\r\n    ];\r\nunion DNSPorts, (union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})))\r\n| where isnotempty(id_resp_p)\r\n| distinct id_resp_p\r\n| extend port_number = tostring(toint(id_resp_p))\r\n| lookup _GetWatchlist('CorelightDNSPortDesc') on port_number\r\n| summarize arg_max(LastUpdatedTimeUTC, *) by port_number\r\n| extend label = iff(isnotempty(description),strcat(description, \" (\", port_number, \")\"), port_number)\r\n| project id_resp_p, label\r\n| sort by label asc",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": "value::all"
                      },
                      {
                        "id": "b0a232f8-a2c1-44c1-9cd4-da150e3df8d8",
                        "version": "KqlParameterItem/1.0",
                        "name": "RecordType",
                        "label": "Record Type",
                        "type": 2,
                        "description": "Select Record Type",
                        "isRequired": true,
                        "query": "let DNSLookup = datatable(\r\n        record_type: string\r\n    )[\r\n        \"A\",\r\n        \"AAAA\",\r\n        \"CNAME\",\r\n        \"MX\",\r\n        \"NB\",\r\n        \"NULL\",\r\n        \"PTR\",\r\n        \"SRV\",\r\n        \"TXT\",\r\n        \"AXFR\",\r\n        \"CAA\",\r\n        \"DNSKEY\",\r\n        \"NS\",\r\n        \"SOA\",\r\n        \"query-38712\"\r\n    ];\r\nunion DNSLookup, (union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})))\r\n| where isnotempty(record_type)\r\n| distinct record_type\r\n| sort by record_type asc\r\n",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 86400000
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": "value::all"
                      },
                      {
                        "id": "55132d85-ab63-4be1-b253-0cd9056e0f69",
                        "version": "KqlParameterItem/1.0",
                        "name": "AdditionalFilter",
                        "label": "Additional Filter",
                        "type": 1,
                        "description": "Enter a keyword to search ",
                        "isRequired": true,
                        "criteriaData": [
                          {
                            "criteriaContext": {
                              "operator": "Default",
                              "resultValType": "static",
                              "resultVal": "*"
                            }
                          }
                        ]
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters - 9"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| search '{AdditionalFilter}'\n| where is_broadcast != \"true\"\n| where isnotempty(query) | count",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Total DNS Requests",
                    "noDataMessage": "No data found",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "leftContent": {
                        "columnMatch": "Count",
                        "formatter": 12,
                        "formatOptions": {
                          "min": -1,
                          "palette": "blue"
                        },
                        "numberFormat": {
                          "unit": 17,
                          "options": {
                            "style": "decimal"
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "25",
                  "name": "query - 19"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| search '{AdditionalFilter}'\n| where is_broadcast != \"true\"\n| where isnotempty(answers) | count",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Total DNS Response",
                    "noDataMessage": "No data found",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "leftContent": {
                        "columnMatch": "Count",
                        "formatter": 12,
                        "formatOptions": {
                          "min": -1,
                          "palette": "blue"
                        },
                        "numberFormat": {
                          "unit": 17,
                          "options": {
                            "style": "decimal"
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "25",
                  "name": "query - 19 - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| search '{AdditionalFilter}'\n| where is_broadcast != \"true\"\n| summarize arg_max(TimeGenerated,*) by session_id, src_ip, dest_ip\n| where reply_code == \"NXDomain\"\n| count",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Top Non-Existent Domains",
                    "noDataMessage": "No data found",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "leftContent": {
                        "columnMatch": "Count",
                        "formatter": 12,
                        "formatOptions": {
                          "min": -1,
                          "palette": "blue"
                        },
                        "numberFormat": {
                          "unit": 17,
                          "options": {
                            "style": "decimal"
                          }
                        }
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "25",
                  "name": "query - 20"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "corelight_dns_agg\n| count\n| extend\n    status_text = iff(Count > 0, \"DNS Agg Logs Available\", \"No DNS Agg Logs\"),\n    status = iff(Count > 0, 1, 0)\n| project status_text, status\n",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "DNS Aggregation (Last 1 Hour)",
                    "noDataMessage": "No data found",
                    "timeContext": {
                      "durationMs": 3600000
                    },
                    "showRefreshButton": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "leftContent": {
                        "columnMatch": "status_text",
                        "formatter": 1
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "25",
                  "name": "query - 20 - Copy"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| search '{AdditionalFilter}'\n| where is_broadcast != \"true\"\n| summarize Sum = count() by record_type\n| top 10 by Sum\n| project RecordType = coalesce(record_type, \"unknown\"), Sum\n",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Top Query Types",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "series",
                    "exportParameterName": "selected_record_type",
                    "exportDefaultValue": "none",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "piechart",
                    "chartSettings": {
                      "createOtherGroup": 10
                    }
                  },
                  "customWidth": "33",
                  "name": "dns_top_query_types"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\nunion\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| search '{AdditionalFilter}'\n| where record_type != \"ptr\" and is_broadcast != \"true\"\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by query\n| extend Count = array_sum(Sparkline) \n| top 10 by Count\n| project Query = coalesce(query, \"unknown\"), Sparkline, Count\n\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top 10 Queries by Count",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "Query",
                    "exportParameterName": "selected_query",
                    "exportDefaultValue": "none",
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Sparkline",
                          "formatter": 9,
                          "formatOptions": {
                            "palette": "greenDark"
                          },
                          "numberFormat": {
                            "unit": 17,
                            "options": {
                              "style": "decimal"
                            }
                          }
                        },
                        {
                          "columnMatch": "Count",
                          "formatter": 0,
                          "numberFormat": {
                            "unit": 17,
                            "options": {
                              "style": "decimal"
                            }
                          }
                        }
                      ],
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "33",
                  "name": "dns_top_queries_by_count"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\nunion\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| search '{AdditionalFilter}'\n| where record_type != \"ptr\" and reply_code == \"NXDomain\" and is_broadcast != \"true\"\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by query\n| extend Count = array_sum(Sparkline) \n| top 10 by Count\n| project Query = coalesce(query, \"unknown\"), Sparkline, Count\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top 10 Queries by Count to Non-Existent Domains",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "Query",
                    "exportParameterName": "selected_nx_query",
                    "exportDefaultValue": "none",
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "formatters": [
                        {
                          "columnMatch": "Sparkline",
                          "formatter": 9,
                          "formatOptions": {
                            "palette": "greenDark"
                          },
                          "numberFormat": {
                            "unit": 17,
                            "options": {
                              "style": "decimal"
                            }
                          }
                        },
                        {
                          "columnMatch": "Count",
                          "formatter": 0,
                          "numberFormat": {
                            "unit": 17,
                            "options": {
                              "style": "decimal"
                            }
                          }
                        }
                      ],
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "33",
                  "name": "dns_top_nxdomain_by_count"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "#### Click on the sections in the above panel **Top Query Types** to view more information.",
                    "style": "info"
                  },
                  "customWidth": "33",
                  "name": "text - 3"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "#### Click on the records in the above panel **Top 10 Queries by Count** to view more information.",
                    "style": "info"
                  },
                  "customWidth": "33",
                  "name": "text - 3"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "#### Click on the records in the above panel **Top 10 Queries by Count to Non-Existent Domains** to view more information.",
                    "style": "info"
                  },
                  "customWidth": "33",
                  "name": "text - 3"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\r\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\r\n| where is_broadcast != \"true\"\r\n| search '{AdditionalFilter}'\r\n| extend record_type = coalesce(record_type, \"unknown\")\r\n| where record_type == '{selected_record_type}'\r\n| extend TTLs = strcat_array(todynamic(TTLs), \",\"), answers = strcat_array(todynamic(answers), \",\"), ttl = strcat_array(todynamic(ttl), \",\")\r\n| project-away $table",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Details for Query Type : {selected_record_type}",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "selected_record_type",
                    "comparison": "isNotEqualTo",
                    "value": "none"
                  },
                  "name": "query - 10",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\r\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\r\n| search '{AdditionalFilter}'\r\n| where record_type != \"ptr\" and is_broadcast != \"true\"\r\n| extend query = coalesce(query, \"unknown\")\r\n| where query =='{selected_query}'\r\n| extend TTLs = strcat_array(todynamic(TTLs), \",\"), answers = strcat_array(todynamic(answers), \",\"), ttl = strcat_array(todynamic(ttl), \",\")\r\n| project-away $table\r\n\r\n",
                    "size": 0,
                    "title": "Details for Query : {selected_query}",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "selected_query",
                    "comparison": "isNotEqualTo",
                    "value": "none"
                  },
                  "name": "query - 11",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\r\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\r\n| search '{AdditionalFilter}'\r\n| where record_type != \"ptr\" and reply_code == \"NXDomain\" and is_broadcast != \"true\"\r\n| extend query = coalesce(query, \"unknown\")\r\n| where query =='{selected_nx_query}'\r\n| extend TTLs = strcat_array(todynamic(TTLs), \",\"), answers = strcat_array(todynamic(answers), \",\"), ttl = strcat_array(todynamic(ttl), \",\")\r\n| project-away $table\r\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Details of Query having Non-Existent Domains : {selected_nx_query}",
                    "noDataMessage": "No data found",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table"
                  },
                  "conditionalVisibility": {
                    "parameterName": "selected_nx_query",
                    "comparison": "isNotEqualTo",
                    "value": "none"
                  },
                  "name": "query - 12",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\n| search '{AdditionalFilter}'\n| where is_broadcast != \"true\"\n| summarize Count = count() by src_ip\n| top 10 by Count\n| project ['Source IP'] = coalesce(src_ip, \"unknown\"), Count",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top Originators by Count",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "Source IP",
                    "exportParameterName": "src",
                    "exportDefaultValue": "none",
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "33",
                  "name": "dns_top_originators",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| search '{AdditionalFilter}'\n| where is_broadcast != \"true\" and isnotempty(query)\n| where record_type==\"PTR\" and reply_code==\"No Error\"\n| summarize Count=count() by Query = query\n| top 20 by Count\n\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top Successful Reverse Queries by Count",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "Query",
                    "exportParameterName": "selected_reverse_query",
                    "exportDefaultValue": "none",
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "33",
                  "name": "dns_top_ptr_by_count",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\n    (corelight_dns_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_dns\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\n| search '{AdditionalFilter}'\n| where isnotempty(query)\n| where record_type == 'PTR' and reply_code == 'NXDomain'\n| summarize Count=count() by Query = query\n| top 10 by Count\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Top Reverse Queries by Count to Non-Existent Domains",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "exportFieldName": "Query",
                    "exportParameterName": "selected_reverse_nx_query",
                    "exportDefaultValue": "none",
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "customWidth": "33",
                  "name": "dns_top_ptr_nxdomain",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 1,
                  "content": {
                    "json": "#### Click on the records in the above panel **Top Originators by Count** to view more information.",
                    "style": "info"
                  },
                  "customWidth": "33",
                  "name": "text - 3"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "#### Click on the records in the above panel **Top Successful Reverse Queries by Count** to view more information.",
                    "style": "info"
                  },
                  "customWidth": "33",
                  "name": "text - 3"
                },
                {
                  "type": 1,
                  "content": {
                    "json": "#### Click on the records in the above panel **Top Reverse Queries by Count to Non-Existent Domains** to view more information.",
                    "style": "info"
                  },
                  "customWidth": "33",
                  "name": "text - 3"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\r\n| where ('*' == ('{RecordType}') or record_type == ('{RecordType}'))\r\n| search '{AdditionalFilter}'\r\n| where is_broadcast != \"true\"\r\n| extend id_orig_h = coalesce(id_orig_h, \"unknown\")\r\n| where id_orig_h == '{src}'\r\n| extend TTLs = strcat_array(todynamic(TTLs), \",\"), answers = strcat_array(todynamic(answers), \",\"), ttl = strcat_array(todynamic(ttl), \",\")\r\n| project-away $table",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Details for Originator : {src}",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "src",
                    "comparison": "isNotEqualTo",
                    "value": "none"
                  },
                  "name": "query - 13",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\r\n| search '{AdditionalFilter}'\r\n| where is_broadcast != \"true\" and query == '{selected_reverse_query}'\r\n| where record_type==\"PTR\" and reply_code==\"No Error\"\r\n| extend TTLs = strcat_array(todynamic(TTLs), \",\"), answers = strcat_array(todynamic(answers), \",\"), ttl = strcat_array(todynamic(ttl), \",\")\r\n| project-away $table\r\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Details for Successful Reverse Query : {selected_reverse_query}",
                    "noDataMessage": "No data found",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "selected_reverse_query",
                    "comparison": "isNotEqualTo",
                    "value": "none"
                  },
                  "name": "query - 14",
                  "styleSettings": {
                    "showBorder": true
                  }
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "union\r\n    (corelight_dns_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_dns\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{ResponderPort}') or id_resp_p == ('{ResponderPort}'))\r\n| search '{AdditionalFilter}'\r\n| where record_type == 'PTR' and reply_code == 'NXDomain'\r\n| where query == '{selected_reverse_nx_query}'\r\n| extend TTLs = strcat_array(todynamic(TTLs), \",\"), answers = strcat_array(todynamic(answers), \",\"), ttl = strcat_array(todynamic(ttl), \",\")\r\n| project-away $table\r\n",
                    "size": 0,
                    "showAnalytics": true,
                    "title": "Details of Reverse Query having Non-Existent Domains : {selected_reverse_nx_query}",
                    "noDataMessage": "No data found.",
                    "timeContextFromParameter": "GlobalTimeRestriction",
                    "showRefreshButton": true,
                    "showExportToExcel": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "table",
                    "gridSettings": {
                      "rowLimit": 10000,
                      "filter": true
                    }
                  },
                  "conditionalVisibility": {
                    "parameterName": "selected_reverse_nx_query",
                    "comparison": "isNotEqualTo",
                    "value": "none"
                  },
                  "name": "query - 15",
                  "styleSettings": {
                    "showBorder": true
                  }
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "corelight_dns"
            },
            "name": "corelight_dns_group"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 1,
                  "content": {
                    "json": "**File analysis is only available for data extracted by Corelight Sensors (open source Zeek sensors not supported)**"
                  },
                  "name": "text - 3"
                },
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "f34f11b1-97e8-45cc-85ed-010931083a1b",
                        "version": "KqlParameterItem/1.0",
                        "name": "ShowAggregation",
                        "label": "Show Aggregation",
                        "type": 2,
                        "isRequired": true,
                        "jsonData": "[\"Yes\", \"No\"]",
                        "value": "No"
                      },
                      {
                        "id": "7893ba65-2d26-4c95-8190-49ce820f2eeb",
                        "version": "KqlParameterItem/1.0",
                        "name": "Mime_Type",
                        "label": "Mime Type",
                        "type": 2,
                        "isRequired": true,
                        "query": "let pre_mime_type = datatable(mime_type: string) [\r\n\"application/chrome-ext\",\r\n\"application/font-woff\",\r\n\"application/font-woff2\",\r\n\"application/javascript\",\r\n\"application/msword\",\r\n\"application/ocsp-request\",\r\n\"application/ocsp-response\",\r\n\"application/soap+xml\",\r\n\"application/vnd.ms-cab-compressed\",\r\n\"application/vnd.ms-fontobject\",\r\n\"application/x-bzip2\",\r\n\"application/x-debian-package\",\r\n\"application/x-dosexec\",\r\n\"application/x-font-ttf\",\r\n\"application/x-rpm\",\r\n\"application/x-shockwave-flash\",\r\n\"application/x-x509-ca-cert\",\r\n\"application/x-x509-user-cert\",\r\n\"application/xml\",\r\n\"application/zip\",\r\n\"image/gif\",\r\n\"image/jpeg\",\r\n\"image/png\",\r\n\"image/x-icon\",\r\n\"image/x-ms-bmp\",\r\n\"text/html\",\r\n\"text/ini\",\r\n\"text/json\",\r\n\"text/plain\",\r\n\"text/x-php\",\r\n\"application/java-archive\",\r\n\"application/pdf\",\r\n\"application/pgp-signature\",\r\n\"application/x-7z-compressed\",\r\n\"application/x-gzip\",\r\n\"application/x-java-applet\",\r\n\"application/x-java-jnlp-file\",\r\n\"application/xml-rpc\",\r\n\"audio/mpeg\",\r\n\"audio/x-mp4a-latm\",\r\n\"audio/x-wav\",\r\n\"image/svg+xml\",\r\n\"text/x-cross-domain-policy\",\r\n\"video/mp4\",\r\n\"application/ogg\",\r\n\"image/jp2\",\r\n\"video/x-flv\",\r\n\"application/x-xz\",\r\n\"application/EDIFACT\",\r\n\"application/alto-costmap+json\",\r\n\"application/pkixcmp\",\r\n\"application/srgs\",\r\n\"application/ttml+xml\",\r\n\"application/vnd-wap-wmlc\",\r\n\"application/vnd.3gpp.mcptt-signed+xml\",\r\n\"application/vnd.3gpp.pic-bw-large\",\r\n\"application/vnd.3gpp2.sms\",\r\n\"application/vnd.accpac.simply.imp\",\r\n\"application/vnd.cybank\",\r\n\"application/vnd.dvb.ait\",\r\n\"application/vnd.ericsson.quickcall\",\r\n\"application/vnd.geospace\",\r\n\"application/vnd.groove-tool-message\",\r\n\"application/vnd.hcl-bireports\",\r\n\"application/vnd.igloader\",\r\n\"application/vnd.innopath.wamp.notification\",\r\n\"application/vnd.iptc.g2.conceptitem+xml\",\r\n\"application/vnd.japannet-payment-wakeup\",\r\n\"application/vnd.marlin.drm.license+xml\",\r\n\"application/vnd.medcalcdata\",\r\n\"application/vnd.ms-windows.nwprinting.oob\",\r\n\"application/vnd.mseq\",\r\n\"application/vnd.nokia.iSDS-radio-presets\",\r\n\"application/vnd.nokia.ncd\",\r\n\"application/vnd.oasis.opendocument.image-template\",\r\n\"application/vnd.openxmlformats-officedocument.drawingml.chart+xml\",\r\n\"application/vnd.openxmlformats-officedocument.spreadsheetml.worksheet+xml\",\r\n\"application/vnd.openxmlformats-officedocument.theme+xml\",\r\n\"application/vnd.osgi.subsystem\",\r\n\"application/vnd.pvi.ptid1\",\r\n\"application/vnd.radisys.moml+xml\",\r\n\"application/vnd.shana.informed.formdata\",\r\n\"application/vnd.software602.filler.form+xml\",\r\n\"application/vnd.uplanet.listcmd-wbxml\",\r\n\"application/vnd.vcx\",\r\n\"application/vnd.wt.stf\"\r\n];\r\n\r\nunion\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| extend mime_type = tostring(mime_type)\r\n| where isnotempty(mime_type) and mime_type != \"application/pkix-cert\"\r\n| project mime_type \r\n| union pre_mime_type\r\n| distinct mime_type\r\n| sort by mime_type asc\r\n\r\n\r\n",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": "value::all"
                      },
                      {
                        "id": "a6972852-6429-4fe8-822a-1b7abe1aa9f4",
                        "version": "KqlParameterItem/1.0",
                        "name": "AdditionalFilter",
                        "label": "Additional Filter",
                        "type": 1,
                        "criteriaData": [
                          {
                            "criteriaContext": {
                              "operator": "Default",
                              "resultValType": "static",
                              "resultVal": "*"
                            }
                          }
                        ],
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction"
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "customWidth": "50",
                  "name": "parameters - 1"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "corelight_files_agg\n| count\n| extend\n    status_text = iff(Count > 0, \"Files Agg Logs Available\", \"No Files Agg Logs\"),\n    status = iff(Count > 0, 1, 0)\n| project status_text, status\n",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "Files Aggregation (Last 1 Hour)",
                    "noDataMessage": "No data found",
                    "timeContext": {
                      "durationMs": 3600000
                    },
                    "showRefreshButton": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "leftContent": {
                        "columnMatch": "status_text",
                        "formatter": 1
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "25",
                  "name": "query - 20 - Copy"
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "tabs",
                    "links": [
                      {
                        "id": "e9a49cbe-fe0a-4a9e-b1b0-e52a3f3b2d0f",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Top Values",
                        "subTarget": "TopValues",
                        "style": "link"
                      },
                      {
                        "id": "c409d048-8fd2-493b-abdc-adea927311a3",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Hosts",
                        "subTarget": "Hosts",
                        "style": "link"
                      }
                    ]
                  },
                  "name": "links - 3"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\n    (corelight_files_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_files\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where array_length(mime_type) > 0\n| mv-expand mime_type\n| where isnotempty(mime_type)\n| extend mime_type = tostring(mime_type)\n| where mime_type != \"application/pkix-cert\" and ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\n| search '{AdditionalFilter}'\n| summarize Count = count() by mime_type\n| sort by Count desc \n| take 10\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Top 10 Mime Types by File Count",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "x",
                                "exportParameterName": "mime_type",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "categoricalbar",
                                "chartSettings": {
                                  "createOtherGroup": 20
                                }
                              },
                              "name": "Top 10 Mime Types by File Count",
                              "styleSettings": {
                                "padding": "20px"
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the bars in the above panel **Top 10 Mime Types by File Count** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "name": "group - 7"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where is_broadcast != \"true\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where mime_type == ('{mime_type}')\r\n| search '{AdditionalFilter}' \r\n| extend analyzers = strcat_array(todynamic(analyzers), \", \"), tx_hosts = strcat_array(todynamic(tx_hosts), \", \"),\r\n         rx_hosts = strcat_array(todynamic(rx_hosts), \", \"), conn_uids = strcat_array(todynamic(conn_uids), \", \"), \r\n         extracted = strcat_array(todynamic(extracted), \", \"), dest_host = strcat_array(todynamic(dest_host), \", \"),\r\n         src_host = strcat_array(todynamic(src_host), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Mime Type: {mime_type}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "mime_type",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 5 - Copy"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where isnotempty(file_name) and\r\n        file_name !contains \"exe\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\r\n| search '{AdditionalFilter}'\r\n| summarize Count = count() by mime_type, filename\r\n| top 15 by Count\r\n| project [\"Mime Type\"] = mime_type, [\"File Name\"] = filename, Count\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Corelight Mime Type to Filename Check",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "File Name",
                              "parameterName": "file_name"
                            },
                            {
                              "fieldName": "Mime Type",
                              "parameterName": "Mime_Type_For_FileName",
                              "parameterType": 1
                            }
                          ],
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 4"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_files_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_files\n    | where '{ShowAggregation}' == \"No\")\n| where isnotempty(app) and\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where array_length(mime_type) > 0\n| mv-expand mime_type\n| where isnotempty(mime_type)\n| extend mime_type = tostring(mime_type)\n| where mime_type != \"application/pkix-cert\" and ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\n| search '{AdditionalFilter}'\n| summarize Count = count() by app\n| top 10 by Count",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Top File Protocols by File Count",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "app",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart"
                        },
                        "customWidth": "50",
                        "name": "Top File Protocols by File Count"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Corelight Mime Type to Filename Check** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **Top File Protocols by File Count** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 10"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where file_name == (@'{file_name}') and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where mime_type == (@'{Mime_Type_For_FileName}')\r\n| search '{AdditionalFilter}'\r\n| extend analyzers = strcat_array(todynamic(analyzers), \", \"), tx_hosts = strcat_array(todynamic(tx_hosts), \", \"),\r\n         rx_hosts = strcat_array(todynamic(rx_hosts), \", \"), conn_uids = strcat_array(todynamic(conn_uids), \", \"), \r\n         extracted = strcat_array(todynamic(extracted), \", \"), dest_host = strcat_array(todynamic(dest_host), \", \"),\r\n         src_host = strcat_array(todynamic(src_host), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Mime Type: {Mime_Type_For_FileName} & File: {file_name}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibilities": [
                          {
                            "parameterName": "file_name",
                            "comparison": "isNotEqualTo"
                          },
                          {
                            "parameterName": "Mime_Type_For_FileName",
                            "comparison": "isNotEqualTo"
                          }
                        ],
                        "name": "query - 7"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where app == ('{app}') and\r\n        is_broadcast != \"true\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where mime_type != \"application/pkix-cert\" and ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\r\n| search '{AdditionalFilter}'\r\n| extend analyzers = strcat_array(todynamic(analyzers), \", \"), tx_hosts = strcat_array(todynamic(tx_hosts), \", \"),\r\n         rx_hosts = strcat_array(todynamic(rx_hosts), \", \"), conn_uids = strcat_array(todynamic(conn_uids), \", \"), \r\n         extracted = strcat_array(todynamic(extracted), \", \"), dest_host = strcat_array(todynamic(dest_host), \", \"),\r\n         src_host = strcat_array(todynamic(src_host), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of File Protocol: {app}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "app",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 5"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_files_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_files\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where array_length(mime_type) > 0\n| mv-expand mime_type\n| where isnotempty(mime_type)\n| extend mime_type = tostring(mime_type)\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\n| search '{AdditionalFilter}'\n| extend NetworkDirection = case(\n    is_src_internal_ip == \"true\" and is_dest_internal_ip == \"false\", \"sent\",\n    is_dest_internal_ip == \"true\" and is_src_internal_ip == \"false\", \"received\",\n    is_dest_internal_ip == \"true\" and is_src_internal_ip == \"true\", \"internal\",\n    \"unknown\"\n)\n| make-series [\"Files Sent\"] = countif(NetworkDirection==\"sent\"),\n              [\"Files Received\"] = countif(NetworkDirection==\"received\"),\n              [\"Files Internal\"] = countif(NetworkDirection==\"internal\"), \n              [\"Files Unknown\"] = countif(NetworkDirection==\"unknown\") \n              on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step {GlobalTimeRestriction:grain} by NetworkDirection\n",
                          "size": 0,
                          "title": "File Flow - # of Files",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "areachart",
                          "tileSettings": {
                            "showBorder": false
                          },
                          "graphSettings": {
                            "type": 0
                          }
                        },
                        "name": "File Flow - # of Files"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_files_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_files\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where array_length(mime_type) > 0\n| mv-expand mime_type\n| where isnotempty(mime_type)\n| extend mime_type = tostring(mime_type)\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\n| search '{AdditionalFilter}'\n| extend NetworkDirection = case(\n    is_src_internal_ip == \"true\" and is_dest_internal_ip == \"false\", \"sent\",\n    is_dest_internal_ip == \"true\" and is_src_internal_ip == \"false\", \"received\",\n    is_dest_internal_ip == \"true\" and is_src_internal_ip == \"true\", \"internal\",\n    \"unknown\"\n)\n| make-series [\"Bytes Sent\"] = sumif(bytes, NetworkDirection==\"sent\"),\n              [\"Bytes Received\"] = sumif(bytes, NetworkDirection==\"received\"),\n              [\"Bytes Internal\"] = sumif(bytes, NetworkDirection==\"internal\"), \n              [\"Bytes Unknown\"] = sumif(bytes, NetworkDirection==\"unknown\") \n              on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step {GlobalTimeRestriction:grain} by NetworkDirection\n",
                          "size": 0,
                          "title": "File Flow - Bytes",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "areachart",
                          "tileSettings": {
                            "showBorder": false
                          },
                          "graphSettings": {
                            "type": 0
                          },
                          "chartSettings": {
                            "ySettings": {
                              "numberFormatSettings": {
                                "unit": 36,
                                "options": {
                                  "style": "decimal",
                                  "useGrouping": true
                                }
                              }
                            }
                          }
                        },
                        "name": "File Flow - Bytes"
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "TopValues"
                  },
                  "name": "deprecated_files"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where is_broadcast != \"true\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\r\n| search '{AdditionalFilter}'\r\n| mv-expand [\"Source Host\"] = todynamic(src_ip)\r\n| where isnotempty([\"Source Host\"])\r\n| summarize [\"Source File Count\"] = count() by tostring([\"Source Host\"])\r\n| top 10 by [\"Source File Count\"]",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Transmitting (src_ip) Hosts - # Files",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 0",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where is_broadcast != \"true\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\r\n| search '{AdditionalFilter}'\r\n| mv-expand [\"Source Host\"] = todynamic(src_ip)\r\n| where isnotempty([\"Source Host\"])\r\n| summarize [\"Source Bytes\"] = sum(bytes) by tostring([\"Source Host\"])\r\n| top 10 by [\"Source Bytes\"]\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Transmitting (src_ip) Hosts - Bytes",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Source Bytes",
                                "formatter": 0,
                                "formatOptions": {
                                  "aggregation": "Count"
                                },
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 0",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where is_broadcast != \"true\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\r\n| search '{AdditionalFilter}'\r\n| mv-expand [\"Destination Host\"] = todynamic(dest_ip)\r\n| where isnotempty([\"Destination Host\"])\r\n| summarize [\"Destination File Count\"] = count() by tostring([\"Destination Host\"])\r\n| top 10 by [\"Destination File Count\"]\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Receiving (dest_ip) Hosts - # Files",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 0",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_files_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_files\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where is_broadcast != \"true\" and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(mime_type) > 0\r\n| mv-expand mime_type\r\n| where isnotempty(mime_type)\r\n| extend mime_type = tostring(mime_type)\r\n| where ('*' == ('{Mime_Type}') or mime_type == ('{Mime_Type}'))\r\n| search '{AdditionalFilter}'\r\n| mv-expand [\"Destination Host\"] = todynamic(dest_ip)\r\n| where isnotempty([\"Destination Host\"])\r\n| summarize [\"Destination Bytes\"] = sum(bytes) by tostring([\"Destination Host\"])\r\n| top 10 by [\"Destination Bytes\"]\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Receiving (dest_ip) Hosts - Bytes",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Destination Bytes",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 0",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "Hosts"
                  },
                  "name": "group - 4"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "corelight_files"
            },
            "name": "corelight_files_group"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "f34f11b1-97e8-45cc-85ed-010931083a1b",
                        "version": "KqlParameterItem/1.0",
                        "name": "ShowAggregation",
                        "label": "Show Aggregation",
                        "type": 2,
                        "isRequired": true,
                        "jsonData": "[\"Yes\", \"No\"]",
                        "value": "No"
                      },
                      {
                        "id": "720c46f5-c415-4f4e-9683-e2cd8694c6a4",
                        "version": "KqlParameterItem/1.0",
                        "name": "UserAgent",
                        "label": "User Agent (Top 100)",
                        "type": 2,
                        "isRequired": true,
                        "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where array_length(user_agent) > 0\r\n| mv-expand user_agent\r\n| where isnotempty(user_agent)\r\n| extend user_agent = tostring(user_agent)\r\n| summarize Count = count() by user_agent\r\n| top 100 by Count \r\n| sort by user_agent asc\r\n| project user_agent\r\n",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 2592000000
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": "value::all"
                      },
                      {
                        "id": "a6972852-6429-4fe8-822a-1b7abe1aa9f4",
                        "version": "KqlParameterItem/1.0",
                        "name": "AdditionalFilter",
                        "label": "Additional Filter",
                        "type": 1,
                        "criteriaData": [
                          {
                            "criteriaContext": {
                              "operator": "Default",
                              "resultValType": "static",
                              "resultVal": "*"
                            }
                          }
                        ],
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction"
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "customWidth": "50",
                  "name": "parameters - 11"
                },
                {
                  "type": 3,
                  "content": {
                    "version": "KqlItem/1.0",
                    "query": "corelight_http_agg\n| count\n| extend\n    status_text = iff(Count > 0, \"HTTP Agg Logs Available\", \"No HTTP Agg Logs\"),\n    status = iff(Count > 0, 1, 0)\n| project status_text, status\n",
                    "size": 3,
                    "showAnalytics": true,
                    "title": "HTTP Aggregation (Last 1 Hour)",
                    "noDataMessage": "No data found",
                    "timeContext": {
                      "durationMs": 3600000
                    },
                    "showRefreshButton": true,
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces",
                    "visualization": "tiles",
                    "tileSettings": {
                      "leftContent": {
                        "columnMatch": "status_text",
                        "formatter": 1
                      },
                      "showBorder": false
                    }
                  },
                  "customWidth": "25",
                  "name": "query - 123"
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "tabs",
                    "links": [
                      {
                        "id": "289a7f8e-6bfa-4411-b794-9e5a5d6174b1",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Top Values",
                        "subTarget": "Top_Values",
                        "style": "link"
                      },
                      {
                        "id": "ee2e2798-6733-4d52-820a-b5ac654240a1",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Details",
                        "subTarget": "Details",
                        "style": "link"
                      },
                      {
                        "id": "37619e94-47cf-408b-a2df-dc7aae4a9dc9",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Directions",
                        "subTarget": "Directions",
                        "style": "link"
                      }
                    ]
                  },
                  "name": "links - 1"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(referrer)\n| search '{AdditionalFilter}'\n| distinct referrer\n| count\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Distinct Referrers",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportParameterName": "Referrer_Count",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "Count",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": false
                          },
                          "textSettings": {
                            "style": "bignumber"
                          }
                        },
                        "customWidth": "16",
                        "name": "http_distinct_referrers"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where array_length(user_agent) > 0\n| mv-expand user_agent\n| where isnotempty(user_agent)\n| extend user_agent = tostring(user_agent)\n| where ('*' == ('{UserAgent}') or user_agent == ('{UserAgent}'))\n| search '{AdditionalFilter}'\n| distinct user_agent\n| count\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Distinct User Agents",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportParameterName": "User_Agent_Count",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "Count",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": false
                          },
                          "textSettings": {
                            "style": "bignumber"
                          }
                        },
                        "customWidth": "16",
                        "name": "query - 17"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(host)\n| search '{AdditionalFilter}'\n| distinct host\n| count\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Distinct Hosts",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportParameterName": "Host_Count",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "Count",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": false
                          },
                          "textSettings": {
                            "style": "bignumber"
                          }
                        },
                        "customWidth": "16",
                        "name": "http_distinct_hosts"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(uid)\n| search '{AdditionalFilter}'\n| distinct uid\n| count\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Distinct Connections",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportParameterName": "Connection_Count",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "Count",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": false
                          },
                          "textSettings": {
                            "style": "bignumber"
                          }
                        },
                        "customWidth": "16",
                        "name": "http_distinct_connections"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(response_body_len)\n| search '{AdditionalFilter}'\n| summarize avg_value = round(avg(response_body_len), 2)\n| project rounded_avg = iff(isnan(avg_value), toreal(0), round(avg_value, 2))\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Average Body Length",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportParameterName": "Average_Body_Length",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "rounded_avg",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": false
                          },
                          "textSettings": {
                            "style": "bignumber"
                          }
                        },
                        "customWidth": "16",
                        "name": "http_avg_response_len"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where array_length(user_agent) > 0\n| mv-expand user_agent\n| where isnotempty(user_agent)\n| extend user_agent = tostring(user_agent)\n| search '{AdditionalFilter}'\n| extend ua_length = strlen(user_agent)\n| summarize avg_value = round(avg(ua_length), 2)\n| project rounded_avg = iff(isnan(avg_value), toreal(0), round(avg_value, 2))\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Average User Agent Length",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportParameterName": "Average_User_Agent_Length",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "rounded_avg",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": false
                          },
                          "textSettings": {
                            "style": "bignumber"
                          }
                        },
                        "customWidth": "16",
                        "name": "http_avg_ua_length"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the any above tile to view more information.",
                          "style": "info"
                        },
                        "name": "text - 1"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(referrer)\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detail of Events with Referrers",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Referrer_Count",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "query - 0",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(user_agent)\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detail of Events with User Agents",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "User_Agent_Count",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "query - 0",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(host)\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detail of Events with Hosts",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Host_Count",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "query - 0",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(uid)\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detail of Events with Connections",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Connection_Count",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "query - 0",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detail of All HTTP Events",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Average_Body_Length",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "query - 0",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detail of All HTTP Events",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "Average_User_Agent_Length",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "query - 0",
                              "styleSettings": {
                                "showBorder": true
                              }
                            }
                          ]
                        },
                        "name": "Tiles Drill Down"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(host_header)\n| search '{AdditionalFilter}'\n| summarize Count = count() by host_header\n| project [\"Host Header\"] = host_header, Count\n| top 20 by Count",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Host Headers by Count",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "Host Header",
                          "exportParameterName": "Top_Host_Header",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true,
                            "sortBy": [
                              {
                                "itemKey": "Count",
                                "sortOrder": 2
                              }
                            ]
                          },
                          "sortBy": [
                            {
                              "itemKey": "Count",
                              "sortOrder": 2
                            }
                          ]
                        },
                        "customWidth": "33",
                        "name": "http_top_hosts"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(status_msg)\n| search '{AdditionalFilter}'\n| summarize Count = count() by status_msg\n| top 10 by Count",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "HTTP Status Code Breakdown",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "Status_Code",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "createOtherGroup": 10
                          }
                        },
                        "customWidth": "33",
                        "name": "http_status_code_chart"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\n\nunion\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where isnotempty(id_orig_h)\n| search '{AdditionalFilter}'\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by id_orig_h\n| extend Count = array_sum(Sparkline)\n| project [\"Source IP\"] = id_orig_h, [\"Originator Over Time\"] = Sparkline, Count\n| top 10 by Count\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Originators",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "Source IP",
                          "exportParameterName": "Top_ID_Orig_H",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Originator Over Time",
                                "formatter": 10,
                                "formatOptions": {
                                  "palette": "blue"
                                }
                              },
                              {
                                "columnMatch": "Originator over time",
                                "formatter": 10,
                                "formatOptions": {
                                  "palette": "blue"
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "33",
                        "name": "http_top_originators"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Top Host Headers by Count** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "33",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **HTTP Status Code Breakdown** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "33",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Top Originators** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "33",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 6"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where host_header == ('{Top_Host_Header}') \r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Host Header: {Top_Host_Header}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Top_Host_Header",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 11",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where status_msg == ('{Status_Code}')\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of HTTP Status: {Status_Code}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Status_Code",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 15",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where id_orig_h == ('{Top_ID_Orig_H}') \r\n| search '{AdditionalFilter}'\r\n| extend user_agent = strcat_array(todynamic(user_agent), \", \"), orig_fuids = strcat_array(todynamic(orig_fuids), \", \"),\r\n         resp_fuids = strcat_array(todynamic(resp_fuids), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \")\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Source: {Top_ID_Orig_H}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true,
                            "sortBy": [
                              {
                                "itemKey": "tags",
                                "sortOrder": 1
                              }
                            ]
                          },
                          "sortBy": [
                            {
                              "itemKey": "tags",
                              "sortOrder": 1
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Top_ID_Orig_H",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 12",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let filter_record = union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where array_length(user_agent) > 0\n| mv-expand user_agent\n| where isnotempty(user_agent)\n| extend user_agent = tostring(user_agent)\n| search '{AdditionalFilter}';\n\nlet total = toscalar(filter_record | count);\n\nfilter_record\n| summarize Count = count() by user_agent\n| extend Percent = round((Count * 100.0 / total), 6)\n| sort by Count asc\n| project [\"HTTP User Agent\"] = user_agent, Count, Percent\n| limit 20\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Rare User Agents",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "HTTP User Agent",
                                "exportParameterName": "Rare_HTTP_User_Agent",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true,
                                  "sortBy": [
                                    {
                                      "itemKey": "Count",
                                      "sortOrder": 2
                                    }
                                  ]
                                },
                                "sortBy": [
                                  {
                                    "itemKey": "Count",
                                    "sortOrder": 2
                                  }
                                ]
                              },
                              "name": "http_rare_ua",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Rare User Agents** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 18"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let filter_record = union\n    (corelight_http_agg\n    | where '{ShowAggregation}' == \"Yes\"),\n    (corelight_http\n    | where '{ShowAggregation}' == \"No\")\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\n| where isnotempty(host_header)\n| search '{AdditionalFilter}';\n\nlet total = toscalar(filter_record | count);\n\nfilter_record \n| summarize Count = count() by host_header\n| extend Percent = round((Count * 100.0 / total), 6)\n| sort by Count asc\n| project [\"Host Header\"] = host_header, Count, Percent\n| limit 20\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Rare Host Headers",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "Host Header",
                                "exportParameterName": "Rare_Host_Header",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true,
                                  "sortBy": [
                                    {
                                      "itemKey": "Count",
                                      "sortOrder": 1
                                    }
                                  ]
                                },
                                "sortBy": [
                                  {
                                    "itemKey": "Count",
                                    "sortOrder": 1
                                  }
                                ]
                              },
                              "name": "http_rare_hosts",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Rare Host Headers** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 19"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where set_has_element(user_agent, '{Rare_HTTP_User_Agent}')\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Rare User Agent: {Rare_HTTP_User_Agent}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Rare_HTTP_User_Agent",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 13",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where host_header == ('{Rare_Host_Header}') \r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Rare Host Header: {Rare_Host_Header}",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Rare_Host_Header",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 14",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "Top_Values"
                  },
                  "name": "group - 2"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "6025317f-629e-497d-8160-10442d1b2e34",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "HTTPMethod",
                                    "label": "HTTP Method",
                                    "type": 2,
                                    "isRequired": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "query": "corelight_http\r\n| where isnotempty(http_method) and\r\n        ('*' == (```{UserAgent}```) or user_agent == (```{UserAgent}```)) and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| distinct http_method\r\n| sort by http_method asc",
                                    "typeSettings": {
                                      "additionalResourceOptions": [
                                        "value::all"
                                      ],
                                      "selectAllValue": "*",
                                      "showDefault": false
                                    },
                                    "timeContext": {
                                      "durationMs": 43200000
                                    },
                                    "timeContextFromParameter": "GlobalTimeRestriction",
                                    "defaultValue": "value::all",
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "pills",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 2"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where ('*' == ('{HTTPMethod}') or http_method == ('{HTTPMethod}'))\r\n| where isnotempty(host_header) \r\n| search '{AdditionalFilter}'\r\n| summarize Count = count() by host_header, http_method\r\n| project [\"Host Header\"] = host_header, [\"HTTP Method\"] = http_method, Count\r\n| sort by Count desc",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Host Breakdown by HTTP Method",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "Host Header",
                                "exportParameterName": "Host_Header",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true,
                                  "sortBy": [
                                    {
                                      "itemKey": "Count",
                                      "sortOrder": 2
                                    }
                                  ]
                                },
                                "sortBy": [
                                  {
                                    "itemKey": "Count",
                                    "sortOrder": 2
                                  }
                                ]
                              },
                              "name": "query - 2",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Host Breakdown by HTTP Method** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 9",
                        "styleSettings": {
                          "maxWidth": "50"
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "850eb07c-9895-4882-ab89-73fd51a945fe",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "HTTPStatus",
                                    "label": "HTTP Status",
                                    "type": 2,
                                    "isRequired": true,
                                    "quote": "'",
                                    "delimiter": ",",
                                    "query": "corelight_http\r\n| where isnotempty(status_code) and\r\n        ('*' == (```{UserAgent}```) or user_agent == (```{UserAgent}```)) and\r\n        ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| distinct status_code\r\n| sort by status_code asc",
                                    "typeSettings": {
                                      "additionalResourceOptions": [
                                        "value::all"
                                      ],
                                      "selectAllValue": "*",
                                      "showDefault": false
                                    },
                                    "timeContext": {
                                      "durationMs": 0
                                    },
                                    "timeContextFromParameter": "GlobalTimeRestriction",
                                    "defaultValue": "value::all",
                                    "queryType": 0,
                                    "resourceType": "microsoft.operationalinsights/workspaces"
                                  }
                                ],
                                "style": "pills",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "customWidth": "50",
                              "name": "parameters - 1",
                              "styleSettings": {
                                "maxWidth": "50"
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where ('*' == ('{HTTPStatus}') or status_code == ('{HTTPStatus}'))\r\n| where isnotempty(host_header) and\r\n        isnotempty(status_code)\r\n| search '{AdditionalFilter}'\r\n| summarize Count = count() by host_header, status_code, status_msg\r\n| project [\"Host Header\"] = host_header, [\"Status Code\"] = status_code, [\"Status Msg\"] = status_msg, Count\r\n| sort by Count desc\r\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Host Breakdown by HTTP Status",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportedParameters": [
                                  {
                                    "fieldName": "Host Header",
                                    "parameterName": "Host_by_Status",
                                    "parameterType": 1
                                  },
                                  {
                                    "fieldName": "",
                                    "parameterName": "Host_Details",
                                    "parameterType": 1
                                  }
                                ],
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "name": "query - 2",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Host Breakdown by HTTP Status** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 10",
                        "styleSettings": {
                          "maxWidth": "50"
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where ('*' == ('{HTTPMethod}') or http_method == ('{HTTPMethod}'))\r\n| where host_header == ('{Host_Header}')\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Host: {Host_Header} by HTTP Method",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true,
                            "sortBy": [
                              {
                                "itemKey": "TimeGenerated",
                                "sortOrder": 1
                              }
                            ]
                          },
                          "sortBy": [
                            {
                              "itemKey": "TimeGenerated",
                              "sortOrder": 1
                            }
                          ]
                        },
                        "conditionalVisibility": {
                          "parameterName": "Host_Header",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 2",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| search '{AdditionalFilter}'\r\n| extend Host_Details = todynamic('{Host_Details}')\r\n| where host_header == Host_Details[\"Host Header\"] and\r\n        status_code == Host_Details[\"Status Code\"] and\r\n        status_msg == Host_Details[\"Status Msg\"]\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Host: {Host_by_Status} by HTTP Status",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Host_Details",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 3",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "Details"
                  },
                  "name": "group - 6"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "**Distinct Host Headers**"
                              },
                              "name": "text - 0"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(host_header) and\r\n        direction in (\"inbound\", \"internal\")\r\n| search '{AdditionalFilter}'\r\n| distinct host_header\r\n| count\r\n",
                                "size": 4,
                                "showAnalytics": true,
                                "title": "Inbound",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "tiles",
                                "tileSettings": {
                                  "leftContent": {
                                    "columnMatch": "Count",
                                    "formatter": 12,
                                    "formatOptions": {
                                      "palette": "greenRed"
                                    },
                                    "numberFormat": {
                                      "unit": 17,
                                      "options": {
                                        "style": "decimal"
                                      }
                                    }
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "50",
                              "name": "query - 1",
                              "styleSettings": {
                                "maxWidth": "50"
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(host_header) and\r\n        direction in (\"outbound\", \"external\")\r\n| search '{AdditionalFilter}'\r\n| distinct host_header\r\n| count\r\n",
                                "size": 4,
                                "showAnalytics": true,
                                "title": "Outbound",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "tiles",
                                "tileSettings": {
                                  "leftContent": {
                                    "columnMatch": "Count",
                                    "formatter": 12,
                                    "formatOptions": {
                                      "palette": "greenRed"
                                    },
                                    "numberFormat": {
                                      "unit": 17,
                                      "options": {
                                        "style": "decimal"
                                      }
                                    }
                                  },
                                  "showBorder": false
                                },
                                "textSettings": {
                                  "style": "bignumber"
                                }
                              },
                              "customWidth": "50",
                              "name": "query - 2",
                              "styleSettings": {
                                "maxWidth": "50"
                              }
                            }
                          ]
                        },
                        "name": "group - 0"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\r\n\r\nunion\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(host_header) and\r\n        direction in (\"inbound\", \"internal\")\r\n| search '{AdditionalFilter}'\r\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by host_header\r\n| extend Count = array_sum(Sparkline)\r\n| project [\"Host Header\"] = host_header, Count, Sparkline\r\n| sort by Count desc\r\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Local Hosts - Inbound",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "Host Header",
                                "exportParameterName": "Host_Header_Inbound",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "Sparkline",
                                      "formatter": 9,
                                      "formatOptions": {
                                        "palette": "greenRed"
                                      }
                                    }
                                  ],
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "name": "query - 3",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Local Hosts - Inbound** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 7"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\r\n\r\nunion\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where isnotempty(host_header) and\r\n        direction in (\"outbound\", \"external\") \r\n| search '{AdditionalFilter}'\r\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by host_header\r\n| extend Count = array_sum(Sparkline)\r\n| project [\"Host Header\"] = host_header, Count, Sparkline\r\n| sort by Count desc\r\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Local Hosts - Outbound",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "Host Header",
                                "exportParameterName": "Host_Header_Outbound",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "Sparkline",
                                      "formatter": 9,
                                      "formatOptions": {
                                        "palette": "greenRed"
                                      }
                                    },
                                    {
                                      "columnMatch": "Trend",
                                      "formatter": 9,
                                      "formatOptions": {
                                        "palette": "blue"
                                      }
                                    }
                                  ],
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "name": "query - 1",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Local Hosts - Outbound** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 4"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where host_header == ('{Host_Header_Inbound}') and\r\n        direction in (\"inbound\", \"internal\")\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Local Host: {Host_Header_Inbound} - Inbound",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Host_Header_Inbound",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where host_header == ('{Host_Header_Outbound}') and\r\n        direction in (\"outbound\", \"external\")  \r\n| search '{AdditionalFilter}'  \r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Local Host: {Host_Header_Outbound} - Outbound",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Host_Header_Outbound",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\r\n\r\nunion\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where array_length(user_agent) > 0 and\r\n        direction in (\"inbound\", \"internal\")\r\n| search '{AdditionalFilter}'\r\n| mv-expand user_agent\r\n| where isnotempty(user_agent)\r\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by tostring(user_agent)\r\n| extend Count = array_sum(Sparkline)\r\n| project [\"HTTP User Agent\"] = tostring(user_agent), Count, Sparkline\r\n| sort by Count\r\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Local User Agents - Inbound",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "HTTP User Agent",
                                "exportParameterName": "User_Agent_Inbound",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "Sparkline",
                                      "formatter": 9,
                                      "formatOptions": {
                                        "palette": "greenRed"
                                      }
                                    }
                                  ],
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "name": "query - 4",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Local User Agents - Inbound** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 8"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\r\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\r\n\r\nunion\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{UserAgent}') or set_has_element(user_agent, '{UserAgent}'))\r\n| where array_length(user_agent) > 0 and\r\n        direction in (\"outbound\", \"external\")\r\n| search '{AdditionalFilter}'\r\n| mv-expand user_agent\r\n| where isnotempty(user_agent)\r\n| make-series Sparkline = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by tostring(user_agent)\r\n| extend Count = array_sum(Sparkline)\r\n| project [\"HTTP User Agent\"] = tostring(user_agent), Count, Sparkline\r\n| sort by Count\r\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Local User Agents - Outbound",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "HTTP User Agent",
                                "exportParameterName": "User_Agent_Outbound",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "Sparkline",
                                      "formatter": 9,
                                      "formatOptions": {
                                        "palette": "greenRed"
                                      }
                                    }
                                  ],
                                  "rowLimit": 10000,
                                  "filter": true
                                }
                              },
                              "name": "query - 2",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Local User Agents - Outbound** to view more information.",
                                "style": "info"
                              },
                              "name": "text - 1"
                            }
                          ],
                          "exportParameters": true
                        },
                        "customWidth": "50",
                        "name": "group - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where set_has_element(user_agent, '{User_Agent_Inbound}') and\r\n        direction in (\"inbound\", \"internal\")\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Local User Agent: {User_Agent_Inbound} - Inbound",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "User_Agent_Inbound",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_http_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_http\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where set_has_element(user_agent, '{User_Agent_Outbound}') and\r\n        direction in (\"outbound\", \"external\")\r\n| search '{AdditionalFilter}'\r\n| extend proxied = strcat_array(todynamic(proxied), \", \"), orig_mime_types = strcat_array(todynamic(orig_mime_types), \", \"),\r\n         orig_fuids = strcat_array(todynamic(orig_fuids), \", \"), resp_fuids = strcat_array(todynamic(resp_fuids), \", \"),\r\n         tags = strcat_array(todynamic(tags), \", \"), resp_mime_types = strcat_array(todynamic(resp_mime_types), \", \"),\r\n         http_content_type = strcat_array(todynamic(http_content_type), \", \"), server_headers = strcat_array(todynamic(server_headers), \", \"),\r\n         client_headers = strcat_array(todynamic(client_headers), \", \")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Local User Agent: {User_Agent_Outbound} - Outbound",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "User_Agent_Outbound",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "Directions"
                  },
                  "name": "group - 5"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "corelight_http"
            },
            "name": "corelight_http_group"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 1,
                  "content": {
                    "json": "#### Software analysis is only available for data extracted by Corelight Sensors (open source Zeek sensors not supported)\r\n\r\n"
                  },
                  "name": "text - 2"
                },
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "715c2033-12a2-44c9-92ea-2cf77980e186",
                        "version": "KqlParameterItem/1.0",
                        "name": "SoftwareType",
                        "label": "Software Type",
                        "type": 2,
                        "description": "Select Software Type",
                        "isRequired": true,
                        "quote": "'",
                        "delimiter": ",",
                        "query": "let SoftwareTypeLookup = datatable(\r\n        software_type: string\r\n    )[\r\n        \"HTTP::APPSERVER\",\r\n        \"HTTP::BROWSER\",\r\n        \"HTTP::SERVER\",\r\n        \"OS::WINDOWS\",\r\n        \"SMTP::MAIL_CLIENT\",\r\n        \"SSH::CLIENT\",\r\n        \"SSH::SERVER\",\r\n        \"FTP::CLIENT\"\r\n    ];\r\nunion SoftwareTypeLookup, (corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})))\r\n| where isnotempty(software_type)\r\n| distinct software_type\r\n| sort by software_type asc\r\n",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "defaultValue": "value::all",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "3ef545d9-49cd-4a14-8e43-061973aa68bb",
                        "version": "KqlParameterItem/1.0",
                        "name": "AdditionalFilter",
                        "label": "Additional Filter",
                        "type": 1,
                        "description": "Enter a keyword to search",
                        "criteriaData": [
                          {
                            "criteriaContext": {
                              "operator": "Default",
                              "resultValType": "static",
                              "resultVal": "*"
                            }
                          }
                        ]
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters - 3"
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "tabs",
                    "links": [
                      {
                        "id": "1fdbc4af-8706-42c1-b8ce-b056ec346e75",
                        "cellValue": "sub_tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Top Values",
                        "subTarget": "top_values",
                        "preText": "Top Values",
                        "style": "link"
                      },
                      {
                        "id": "da271aed-791d-4b20-bf17-17772785b1f2",
                        "cellValue": "sub_tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Details",
                        "subTarget": "details",
                        "style": "link"
                      }
                    ]
                  },
                  "name": "links - 1"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\n| search '{AdditionalFilter}'\n| where isnotempty(name)\n| summarize Count = count() by name\n| top 10 by Count",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Top Software",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "name",
                          "exportDefaultValue": "none",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "yAxis": [
                              "Count"
                            ],
                            "createOtherGroup": 10,
                            "ySettings": {
                              "numberFormatSettings": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal",
                                  "useGrouping": true
                                }
                              }
                            }
                          }
                        },
                        "name": "Top Software",
                        "styleSettings": {
                          "padding": "0% 25% 0% 25%"
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the sections in the above panel **Top Software** to view more information.",
                          "style": "info"
                        },
                        "name": "text - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\r\n| search '{AdditionalFilter}'\r\n| where name == '{name}'\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for Software : {name}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "name",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 3",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\n| search '{AdditionalFilter}'\n| where isnotempty(name) and isnotempty(version)\n| summarize Count = count() by name, version\n| as T\n| extend Percentage = round(Count * 100.0 / toscalar(T | summarize sum(Count)), 2)\n| top 10 by Count\n| project-rename [\"Software Name\"]=name, Version=version",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Software Versions",
                          "noDataMessage": "No data found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "Software Name",
                              "parameterName": "software_name",
                              "parameterType": 1,
                              "defaultValue": "none"
                            },
                            {
                              "fieldName": "Version",
                              "parameterName": "version",
                              "parameterType": 1,
                              "defaultValue": "none"
                            }
                          ],
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Count",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 17,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              },
                              {
                                "columnMatch": "Percentage",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 1,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "Top Software Versions",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\n| search '{AdditionalFilter}'\n| where isnotempty(name)\n| summarize Count = count() by name\n| top 10 by Count\n| project-rename ['Name'] = name",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Software Types",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "Name",
                          "exportParameterName": "name",
                          "exportDefaultValue": "none",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Count",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 17,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "Top Software Types",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **Top Software Versions** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 3"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **Top Software Types** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\r\n| search '{AdditionalFilter}'\r\n| where name == '{software_name}' and version == '{version}'\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details of Software Name : {software_name} and Version : {version}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibilities": [
                          {
                            "parameterName": "software_name",
                            "comparison": "isNotEqualTo",
                            "value": "none"
                          },
                          {
                            "parameterName": "version",
                            "comparison": "isNotEqualTo",
                            "value": "none"
                          }
                        ],
                        "name": "query - 4",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\r\n| search '{AdditionalFilter}'\r\n| where name == '{name}'\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for Software Type : {name}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "name",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "sub_tab",
                    "comparison": "isEqualTo",
                    "value": "top_values"
                  },
                  "name": "top_values"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "41c6d57b-46c0-4ab1-a8d1-ed24b38a9bb4",
                              "version": "KqlParameterItem/1.0",
                              "name": "Host",
                              "type": 2,
                              "description": "Select Host",
                              "isRequired": true,
                              "quote": "'",
                              "delimiter": ",",
                              "query": "corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\r\n| where isnotempty(tx_host)\r\n| distinct tx_host\r\n| sort by tx_host asc\r\n",
                              "typeSettings": {
                                "additionalResourceOptions": [
                                  "value::all"
                                ],
                                "selectAllValue": "*",
                                "showDefault": false
                              },
                              "timeContext": {
                                "durationMs": 0
                              },
                              "timeContextFromParameter": "GlobalTimeRestriction",
                              "defaultValue": "value::all",
                              "queryType": 0,
                              "resourceType": "microsoft.operationalinsights/workspaces"
                            },
                            {
                              "id": "c3384feb-36bf-43fe-b7b8-532306d7b606",
                              "version": "KqlParameterItem/1.0",
                              "name": "Software",
                              "type": 2,
                              "description": "Select Software Name",
                              "isRequired": true,
                              "quote": "'",
                              "delimiter": ",",
                              "query": "corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\r\n| where isnotempty(name)\r\n| distinct name\r\n| sort by name asc\r\n",
                              "typeSettings": {
                                "additionalResourceOptions": [
                                  "value::all"
                                ],
                                "selectAllValue": "*",
                                "showDefault": false
                              },
                              "timeContext": {
                                "durationMs": 0
                              },
                              "timeContextFromParameter": "GlobalTimeRestriction",
                              "defaultValue": "value::all",
                              "queryType": 0,
                              "resourceType": "microsoft.operationalinsights/workspaces"
                            }
                          ],
                          "style": "pills",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "name": "parameters - 0"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_software\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where ('*' == ('{SoftwareType}') or software_type == ('{SoftwareType}'))\r\n| search '{AdditionalFilter}'\r\n| where ('*' == ('{Host}') or tx_host == ('{Host}'))\r\n| where ('*' == ('{Software}') or name == ('{Software}'))\r\n| project ['Time Generated'] = TimeGenerated,[\"Source Port\"]=src_port, Source=tx_host, [\"Software Name\"]=name, Version=version, ['Additional Version']=version_addl, ['Software Type']=software_type, [\"Unparsed Version\"]=unparsed_version",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Software Details",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "Tx Host",
                          "exportParameterName": "txhost",
                          "exportDefaultValue": "none",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "name": "query - 1",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "sub_tab",
                    "comparison": "isEqualTo",
                    "value": "details"
                  },
                  "name": "software_details"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "corelight_software"
            },
            "name": "corelight_software_group"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 1,
                  "content": {
                    "json": "#### x509 analysis is only available for data extracted by Corelight Sensors (open source Zeek sensors not supported)\r\n\r\n"
                  },
                  "name": "text - 0"
                },
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "da3148d3-08c3-4a3b-9eff-ad559bb0ca68",
                        "version": "KqlParameterItem/1.0",
                        "name": "Direction",
                        "type": 2,
                        "description": "Select Direction",
                        "isRequired": true,
                        "quote": "'",
                        "delimiter": ",",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "jsonData": "[\r\n    { \"value\":\"External\"},\r\n    { \"value\":\"Internal\"},\r\n    { \"value\":\"Inbound\"},\r\n    { \"value\":\"Outbound\"}\r\n]",
                        "defaultValue": "value::all"
                      },
                      {
                        "id": "a6972852-6429-4fe8-822a-1b7abe1aa9f4",
                        "version": "KqlParameterItem/1.0",
                        "name": "AdditionalFilter",
                        "label": "Additional Filter",
                        "type": 1,
                        "description": "Enter a keyword to search",
                        "criteriaData": [
                          {
                            "criteriaContext": {
                              "operator": "Default",
                              "resultValType": "static",
                              "resultVal": "*"
                            }
                          }
                        ],
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "TimeRestriction"
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters - 11"
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "tabs",
                    "links": [
                      {
                        "id": "bc62a236-4bb8-4fd4-92cb-e13e4c545a6b",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "Top Values",
                        "subTarget": "TopValues",
                        "style": "link"
                      },
                      {
                        "id": "b44e3acc-5c3b-434b-9138-28e9d44decd3",
                        "cellValue": "Tab",
                        "linkTarget": "parameter",
                        "linkLabel": "x509",
                        "subTarget": "x509",
                        "style": "link"
                      }
                    ]
                  },
                  "name": "links - 1"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "8dce76f0-a347-43e4-bc55-0d24ae64b34e",
                              "version": "KqlParameterItem/1.0",
                              "name": "ShowAggregation",
                              "label": "Show Aggregation",
                              "type": 2,
                              "isRequired": true,
                              "jsonData": "[\"Yes\",\"No\"]",
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "No"
                            }
                          ],
                          "style": "pills",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "customWidth": "25",
                        "name": "parameters - 9"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_ssl_agg\n| count\n| extend\n    status_text = iff(Count > 0, \"SSL Agg Logs Available\", \"No SSL Agg Logs\"),\n    status = iff(Count > 0, 1, 0)\n| project status_text, status\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "SSL Aggregation (Last 1 Hour)",
                          "noDataMessage": "No data found",
                          "timeContext": {
                            "durationMs": 3600000
                          },
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "leftContent": {
                              "columnMatch": "status_text",
                              "formatter": 1
                            },
                            "showBorder": false
                          }
                        },
                        "customWidth": "25",
                        "name": "query - 10"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let TotalRecords = (union\r\n    (corelight_ssl_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_ssl\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) and\r\n        ('*' == ('{Direction}') or direction == tolower('{Direction}'))\r\n| search '{AdditionalFilter}'\r\n| extend ['SSL Subject'] = coalesce(ssl_subject, ssl_subject_common_name)\r\n| where isnotempty(['SSL Subject']));\r\nlet Total = toscalar(TotalRecords\r\n| count);\r\nTotalRecords\r\n| summarize Count = count() by ['SSL Subject']\r\n| extend Percent = round((Count * 100.0 / Total), 6)\r\n| top 10 by Count\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Certificate Subjects",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "SSL Subject",
                          "exportParameterName": "selected_ssl_subject",
                          "exportDefaultValue": "none",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Percent",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 1,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "name": "query - 0",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **Top Certificate Subjects** to view more information.",
                          "style": "info"
                        },
                        "name": "text - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_ssl_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_ssl\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) and\r\n        ('*' == ('{Direction}') or direction == tolower('{Direction}'))\r\n| search '{AdditionalFilter}'\r\n| extend ['SSL Subject'] = coalesce(ssl_subject, ssl_subject_common_name)\r\n| where ['SSL Subject'] == @'{selected_ssl_subject}'\r\n| extend cert_chain_fps = strcat_array(todynamic(cert_chain_fps), \",\"), client_cert_chain_fps = strcat_array(todynamic(client_cert_chain_fps), \",\"), fingerprint = strcat_array(todynamic(fingerprint), \",\")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for Certificate Subject : {selected_ssl_subject}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "selected_ssl_subject",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 3",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let TotalRecords = union\r\n    (corelight_ssl_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_ssl\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) and\r\n        ('*' == ('{Direction}') or direction == tolower('{Direction}'))\r\n| search '{AdditionalFilter}'\r\n| where (direction == \"internal\" or direction == \"inbound\") and isnotempty(validation_status);\r\nlet Total = toscalar(TotalRecords\r\n| count);\r\nTotalRecords\r\n| summarize Count = count() by validation_status\r\n| extend Percent = round((Count * 100.0 / Total), 6)\r\n| top 10 by Count\r\n| project-rename ['Validation Status'] = validation_status",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top Local Responders - Validation Status",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "Validation Status",
                          "exportParameterName": "validation_status",
                          "exportDefaultValue": "none",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Percent",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 1,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 1"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_ssl_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_ssl\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) and\r\n        ('*' == ('{Direction}') or direction == tolower('{Direction}'))\r\n| search '{AdditionalFilter}'\r\n| where isnotempty(ssl_cipher)\r\n| summarize Count = count() by ssl_cipher\r\n| top 10 by Count",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Top Ciphers",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "ssl_cipher",
                          "exportDefaultValue": "none",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "createOtherGroup": 10
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 2"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **Top Local Responders - Validation Status** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 3"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the sections in the above panel **Top Ciphers** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_ssl_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_ssl\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) and\r\n        ('*' == ('{Direction}') or direction == tolower('{Direction}'))\r\n| search '{AdditionalFilter}'\r\n| where (direction == \"internal\" or direction == \"inbound\") and\r\n        is_broadcast != \"true\" and validation_status == '{validation_status}'\r\n| extend cert_chain_fps = strcat_array(todynamic(cert_chain_fps), \",\"), client_cert_chain_fps = strcat_array(todynamic(client_cert_chain_fps), \",\"), fingerprint = strcat_array(todynamic(fingerprint), \",\")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for Validation Status : {validation_status}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "validation_status",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union\r\n    (corelight_ssl_agg\r\n    | where '{ShowAggregation}' == \"Yes\"),\r\n    (corelight_ssl\r\n    | where '{ShowAggregation}' == \"No\")\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor})) and\r\n        ('*' == ('{Direction}') or direction == tolower('{Direction}'))\r\n| search '{AdditionalFilter}'\r\n| where ssl_cipher == '{ssl_cipher}'\r\n| extend cert_chain_fps = strcat_array(todynamic(cert_chain_fps), \",\"), client_cert_chain_fps = strcat_array(todynamic(client_cert_chain_fps), \",\"), fingerprint = strcat_array(todynamic(fingerprint), \",\")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for Cipher : {ssl_cipher}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "ssl_cipher",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 4",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "TopValues"
                  },
                  "name": "group - 0"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let TopSubjects = (corelight_x509\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| where isnotempty(ssl_subject));\r\nlet Total = toscalar(TopSubjects\r\n| count\r\n);\r\nTopSubjects\r\n| summarize Count = count() by ssl_subject\r\n| extend Percentage = round((Count*100.0)/Total, 6)\r\n| top 10 by Count desc\r\n| project-rename ['SSL Subject'] = ssl_subject",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "x509 Top Subjects",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "SSL Subject",
                          "exportParameterName": "ssl_subject",
                          "exportDefaultValue": "none",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Percentage",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 1,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true,
                            "sortBy": [
                              {
                                "itemKey": "Count",
                                "sortOrder": 2
                              }
                            ]
                          },
                          "sortBy": [
                            {
                              "itemKey": "Count",
                              "sortOrder": 2
                            }
                          ]
                        },
                        "customWidth": "50",
                        "name": "query - 2",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let TopSubjects = (corelight_x509\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| where isnotempty(ssl_subject));\r\nlet Total = toscalar(TopSubjects\r\n| count\r\n);\r\nTopSubjects\r\n| summarize Count = count() by ssl_subject\r\n| extend Percentage = round((Count*100.0)/Total, 6)\r\n| sort by Count asc\r\n| limit 10\r\n| project-rename ['SSL Subject'] = ssl_subject",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "x509 Rare Subjects",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "SSL Subject",
                          "exportParameterName": "rare_ssl_subject",
                          "exportDefaultValue": "none",
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Percentage",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 1,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "customWidth": "50",
                        "name": "query - 3",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **x509 Top Subjects** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 3"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **x509 Rare Subjects** to view more information.",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_x509\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| where ssl_subject == @'{ssl_subject}'\r\n| extend san_dns = strcat_array(todynamic(san_dns), \",\"), san_uri = strcat_array(todynamic(san_uri), \",\"), san_email = strcat_array(todynamic(san_email), \",\"), san_ip = strcat_array(todynamic(san_ip), \",\")\r\n| project-away $table",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for x509 Top Subject : {ssl_subject}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "ssl_subject",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 5",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_x509\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| where ssl_subject == @'{rare_ssl_subject}'\r\n| extend san_dns = strcat_array(todynamic(san_dns), \",\"), san_uri = strcat_array(todynamic(san_uri), \",\"), san_email = strcat_array(todynamic(san_email), \",\"), san_ip = strcat_array(todynamic(san_ip), \",\")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for x509 Rare Subject : {rare_ssl_subject}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "rare_ssl_subject",
                          "comparison": "isNotEqualTo",
                          "value": "none"
                        },
                        "name": "query - 6",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_x509\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| extend days_to_expiry_by_end_time = datetime_diff('day', todatetime(ssl_end_time), now())\r\n| where days_to_expiry_by_end_time < 0\r\n| summarize Count = count() by ssl_end_time, ssl_subject, ssl_issuer\r\n| project-rename ['SSL Subject'] = ssl_subject, ['SSL Issuer'] = ssl_issuer, ['SSL End Time'] = ssl_end_time\r\n| sort by Count desc",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "x509 Expired Certificates",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "SSL End Time",
                              "parameterName": "ssl_end_time",
                              "parameterType": 1,
                              "defaultValue": "none"
                            },
                            {
                              "fieldName": "SSL Subject",
                              "parameterName": "Subject",
                              "parameterType": 1,
                              "defaultValue": "none"
                            },
                            {
                              "fieldName": "SSL Issuer",
                              "parameterName": "Issuer",
                              "parameterType": 1
                            }
                          ],
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "name": "query - 9",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **x509 Expired Certificates** to view more information.",
                          "style": "info"
                        },
                        "name": "text - 3"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_x509\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| search '{AdditionalFilter}'\r\n| where days_to_expiry <= 0\r\n| where  ssl_end_time == '{ssl_end_time}' and ssl_subject == '{Subject}' and ssl_issuer == '{Issuer}'\r\n| extend san_dns = strcat_array(todynamic(san_dns), \",\"), san_uri = strcat_array(todynamic(san_uri), \",\"), san_email = strcat_array(todynamic(san_email), \",\"), san_ip = strcat_array(todynamic(san_ip), \",\")\r\n| project-away $table\r\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Details for x509 Certificate having Subject : {Subject}, Issuer : {Issuer} and SSL End Date : {ssl_end_time}",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibilities": [
                          {
                            "parameterName": "ssl_end_time",
                            "comparison": "isNotEqualTo",
                            "value": "none"
                          },
                          {
                            "parameterName": "Subject",
                            "comparison": "isNotEqualTo",
                            "value": "none"
                          }
                        ],
                        "name": "query - 7",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "Tab",
                    "comparison": "isEqualTo",
                    "value": "x509"
                  },
                  "name": "x509"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "corelight_ssl_x509"
            },
            "name": "SSL and x509"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 1,
                  "content": {
                    "json": "\nDashboard to visualize AWS VPC Flow data captured by Corelight."
                  },
                  "name": "workbook-header"
                },
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "param-vpc-id",
                        "version": "KqlParameterItem/1.0",
                        "name": "VpcId",
                        "label": "VPC ID",
                        "type": 2,
                        "isRequired": true,
                        "multiSelect": true,
                        "query": "// KQL query to populate VPC IDs\r\ncorelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where capture_source == \"vpcflow\" and isnotempty(capture_metadata_vpc_vpc_id)\r\n| distinct capture_metadata_vpc_vpc_id",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 0
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": [
                          "value::all"
                        ]
                      },
                      {
                        "id": "param-org-id",
                        "version": "KqlParameterItem/1.0",
                        "name": "OrgId",
                        "label": "AWS Organization ID",
                        "type": 2,
                        "isRequired": true,
                        "query": "// KQL query to populate AWS Org IDs\r\ncorelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\r\n| where capture_source == \"vpcflow\" \r\n| where isnotempty(orig_inst_org_id) or isnotempty(resp_inst_org_id)\r\n| extend org_id=coalesce(orig_inst_org_id, resp_inst_org_id)\r\n| distinct org_id",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContext": {
                          "durationMs": 86400000
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": "value::all"
                      },
                      {
                        "id": "param-direction",
                        "version": "KqlParameterItem/1.0",
                        "name": "Direction",
                        "type": 2,
                        "isRequired": true,
                        "multiSelect": true,
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "jsonData": "[{\"value\":\"*\",\"label\":\"All\"},{\"value\":\"external\",\"label\":\"External\"},{\"value\":\"inbound\",\"label\":\"Inbound\"},{\"value\":\"internal\",\"label\":\"Internal\"},{\"value\":\"outbound\",\"label\":\"Outbound\"}]",
                        "value": [
                          "value::all"
                        ]
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters-global"
                },
                {
                  "type": 11,
                  "content": {
                    "version": "LinkItem/1.0",
                    "style": "tabs",
                    "links": [
                      {
                        "id": "tab-overview",
                        "cellValue": "selectedTab",
                        "linkTarget": "parameter",
                        "linkLabel": "Overview",
                        "subTarget": "overview",
                        "style": "link"
                      },
                      {
                        "id": "tab-ip-interrogation",
                        "cellValue": "selectedTab",
                        "linkTarget": "parameter",
                        "linkLabel": "IP Interrogation",
                        "subTarget": "ip-interrogation",
                        "style": "link"
                      }
                    ]
                  },
                  "name": "tabs-navigation"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize total_volume = sum(bytes)\n| project-rename [\"Total Volume\"] = total_volume",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Total Volume",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "Total Volume",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 36,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": true
                          },
                          "statSettings": {
                            "valueAggregation": "None",
                            "colorSettings": {
                              "type": "static",
                              "mode": "background",
                              "staticColor": "green",
                              "heatmapPalette": "greenRed"
                            },
                            "tagText": "",
                            "valueFontStyle": "smallPlus"
                          }
                        },
                        "customWidth": "17",
                        "name": "tile-total-volume"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let interval_in_hrs=datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days=datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\nlet TotalConnections=(corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize total_connections = dcount(session_id) | project total_connections);\nlet trendline=toscalar(\n    corelight_conn\n    | where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n    | where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n    | where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n    | where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n    | where capture_source == \"vpcflow\" and transport != \"icmp\"\n    | make-series Trend = dcount(session_id) default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration | project Trend);\nTotalConnections\n| extend Trend = trendline\n                                      ",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Total Connections",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "total_connections",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "secondaryContent": {
                              "columnMatch": "Trend",
                              "formatter": 9,
                              "formatOptions": {
                                "min": 0,
                                "palette": "blue"
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "17",
                        "name": "tile-total-connections"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let interval_in_hrs=datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days=datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\nlet SrcIP=(corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize src_ips = dcount(src_ip) | project src_ips);\nlet trendline=toscalar(\n    corelight_conn\n    | where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n    | where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n    | where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n    | where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n    | where capture_source == \"vpcflow\" and transport != \"icmp\"\n    | make-series Trend = dcount(src_ip) default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration | project Trend);\nSrcIP\n| extend Trend = trendline\n                                      ",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Unique Source IPs",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "src_ips",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "secondaryContent": {
                              "columnMatch": "Trend",
                              "formatter": 9,
                              "formatOptions": {
                                "palette": "blue"
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "17",
                        "name": "tile-unique-source-ips"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let interval_in_hrs=datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days=datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\nlet DestinationIP=(corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize unique_destination_ips = dcount(dest_ip) | project unique_destination_ips);\nlet trendline=toscalar(\n    corelight_conn\n    | where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n    | where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n    | where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n    | where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n    | where capture_source == \"vpcflow\" and transport != \"icmp\"\n    | make-series Trend = dcount(dest_ip) default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration | project Trend);\nDestinationIP\n| extend Trend = trendline\n                                      ",
                          "size": 4,
                          "title": "Unique Destination IPs",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "unique_destination_ips",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "secondaryContent": {
                              "columnMatch": "Trend",
                              "formatter": 9,
                              "formatOptions": {
                                "palette": "blue"
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "17",
                        "name": "tile-unique-dest-ips"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\"\n| summarize enriched_count = countif(isnotempty(orig_inst_org_id) or isnotempty(resp_inst_org_id))\n| extend [\"Cloud Enrichment\"] = iff(enriched_count > 0, \"Enriched Conn Logs are Present\", \"Enriched Conn Logs are not Present\")\n| project [\"Cloud Enrichment\"]",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Cloud Enrichment",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "Cloud Enrichment",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "blue",
                                "compositeBarSettings": {
                                  "labelText": "",
                                  "columnSettings": [
                                    {
                                      "columnName": "Cloud Enrichment",
                                      "color": "lightBlue"
                                    }
                                  ]
                                }
                              }
                            },
                            "showBorder": false,
                            "size": "auto"
                          },
                          "statSettings": {
                            "valueAggregation": "None",
                            "colorSettings": {
                              "type": "static",
                              "mode": "background",
                              "staticColor": "green",
                              "heatmapPalette": "greenRed"
                            },
                            "tagText": "",
                            "valueFontStyle": "smallPlus"
                          },
                          "textSettings": {
                            "style": "header"
                          }
                        },
                        "customWidth": "31",
                        "name": "tile-cloud-enrichment"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize total_bytes = sum(bytes_out) by src_ip\n| top 10 by total_bytes desc\n| project-rename\n    [\"Source IP\"] = src_ip,\n    [\"Total Bytes Sent\"] = total_bytes",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top 10 Source IPs with Most Sent Data",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Total Bytes Sent",
                                "formatter": 1,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal",
                                    "useGrouping": false
                                  }
                                }
                              },
                              {
                                "columnMatch": "selectedTab",
                                "formatter": 5
                              }
                            ]
                          }
                        },
                        "customWidth": "25",
                        "name": "table-top-source-ips",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize total_bytes = sum(bytes_in) by dest_ip\n| top 10 by total_bytes desc\n| project-rename\n    [\"Destination IP\"] = dest_ip,\n    [\"Total Bytes Received\"] = total_bytes",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top 10 Destination IPs with Most Received Data",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Total Bytes Received",
                                "formatter": 1,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal",
                                    "useGrouping": false
                                  }
                                }
                              }
                            ]
                          }
                        },
                        "customWidth": "25",
                        "name": "table-top-dest-ips",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let interval_in_hrs= datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days= datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\ncorelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| make-series  [\"Bytes Out\"] = sum(bytes_out), [\"Bytes In\"] = sum(bytes_in)  default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by direction\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Traffic by Direction and Bytes Transferred over Time",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "areachart",
                          "chartSettings": {
                            "createOtherGroup": 0,
                            "seriesLabelSettings": [
                              {
                                "seriesName": "inbound",
                                "color": "green"
                              },
                              {
                                "seriesName": "outbound",
                                "color": "blue"
                              }
                            ],
                            "xSettings": {
                              "label": ""
                            }
                          }
                        },
                        "customWidth": "50",
                        "name": "chart-traffic-over-time",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 9,
                              "content": {
                                "version": "KqlParameterItem/1.0",
                                "parameters": [
                                  {
                                    "id": "1c6a653c-fd65-4c0e-aced-bd8cb5738906",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "source_ip",
                                    "label": "Source IP",
                                    "type": 1,
                                    "isRequired": true,
                                    "timeContext": {
                                      "durationMs": 86400000
                                    },
                                    "value": "*"
                                  },
                                  {
                                    "id": "d9481a5d-11a8-4bb1-bca0-82d46910cb77",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "protocol",
                                    "label": "Protocol",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "*"
                                  },
                                  {
                                    "id": "631c3bf8-66aa-4b91-b743-8cc96d8479ca",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "destination_port",
                                    "label": "Destination Port",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "*"
                                  },
                                  {
                                    "id": "d7c327e6-73c7-4554-91e0-d56940f76816",
                                    "version": "KqlParameterItem/1.0",
                                    "name": "destination_ip",
                                    "label": "Destination IP",
                                    "type": 1,
                                    "isRequired": true,
                                    "value": "*"
                                  }
                                ],
                                "style": "pills",
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces"
                              },
                              "name": "parameters - 1"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where (\"{source_ip}\" == \"*\" or src_ip == \"{source_ip}\") and (\"{destination_port}\" == \"*\" or dest_port == \"{destination_port}\") and (\"{destination_ip}\" == \"*\" or dest_ip == \"{destination_ip}\") and (\"{protocol}\" == \"*\" or proto == \"{protocol}\")\n| summarize connections = dcount(session_id) by src_ip, transport, dest_port, dest_ip\n| top 20 by connections desc\n| project-rename\n    [\"Source IP\"] = src_ip,\n    [\"Protocol\"] = transport,\n    [\"Destination Port\"] = dest_port,\n    [\"Destination IP\"] = dest_ip,\n    [\"Connection Count\"] = connections\n| sort by [\"Connection Count\"] desc",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Connections between Source IPs and Destination IPs",
                                "noDataMessage": "No Data Found",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "table",
                                "gridSettings": {
                                  "formatters": [
                                    {
                                      "columnMatch": "Destination Port",
                                      "formatter": 1
                                    },
                                    {
                                      "columnMatch": "Connection Count",
                                      "formatter": 1,
                                      "numberFormat": {
                                        "unit": 17,
                                        "options": {
                                          "style": "decimal"
                                        }
                                      }
                                    }
                                  ]
                                },
                                "graphSettings": {
                                  "type": 0,
                                  "topContent": {
                                    "columnMatch": "Source IP",
                                    "formatter": 1
                                  },
                                  "leftContent": {
                                    "columnMatch": "Source IP"
                                  },
                                  "centerContent": {
                                    "columnMatch": "Destination Port",
                                    "formatter": 1,
                                    "numberFormat": {
                                      "unit": 17,
                                      "options": {
                                        "maximumSignificantDigits": 3,
                                        "maximumFractionDigits": 2
                                      }
                                    }
                                  },
                                  "rightContent": {
                                    "columnMatch": "Destination Port"
                                  },
                                  "bottomContent": {
                                    "columnMatch": "Volume"
                                  },
                                  "nodeIdField": "Source IP",
                                  "sourceIdField": "Destination Port",
                                  "targetIdField": "Volume",
                                  "graphOrientation": 3,
                                  "showOrientationToggles": false,
                                  "staticNodeSize": 100,
                                  "hivesMargin": 5
                                }
                              },
                              "customWidth": "60",
                              "name": "graph-src-dest-connections",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| extend transport_port = strcat(transport, \"/\", tostring(dest_port))\n| summarize count() by transport_port\n| top 20 by count_ desc\n| project-rename\n    [\"Transport/Port\"] = transport_port,\n    [\"Count\"] = count_",
                                "size": 3,
                                "showAnalytics": true,
                                "title": "Top 20 Protocol and Port Distribution",
                                "noDataMessage": "No Data Found",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "piechart"
                              },
                              "customWidth": "40",
                              "name": "pie-protocol-distribution",
                              "styleSettings": {
                                "padding": "20px"
                              }
                            }
                          ]
                        },
                        "name": "group - 22"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize volume = sum(bytes) by src_ip, dest_port\n| top 20 by volume desc\n| project-rename\n    [\"Source IP\"] = src_ip,\n    [\"Destination Port\"] = dest_port,\n    [\"Volume\"] = volume",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Top 20 Largest Byte Transfers",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Source IP",
                                "formatter": 1
                              },
                              {
                                "columnMatch": "Destination Port",
                                "formatter": 1
                              },
                              {
                                "columnMatch": "Volume",
                                "formatter": 1,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ]
                          }
                        },
                        "customWidth": "50",
                        "name": "sankey-byte-transfers",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value}))\n| where direction == \"outbound\" and duration > 0\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| project duration, bytes_out, src_ip",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Outbound Connection Outliers",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "scatterchart",
                          "chartSettings": {
                            "xAxis": "bytes_out",
                            "yAxis": [
                              "duration"
                            ],
                            "xSettings": {
                              "numberFormatSettings": {
                                "unit": 2,
                                "options": {
                                  "style": "decimal",
                                  "useGrouping": false
                                }
                              },
                              "label": ""
                            },
                            "ySettings": {
                              "scale": "time",
                              "label": "Duration (ms)"
                            }
                          }
                        },
                        "customWidth": "50",
                        "name": "scatter-connection-outliers",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == \"inbound\"\n| where capture_source == \"vpcflow\"\n| where isnotempty(src_country)\n| summarize connections = count() by src_country\n| extend iso2 = src_country\n| lookup _GetWatchlist('CorelightGeoCountries') on iso2\n| project country, connections",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Inbound Connections by Source Country",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "map",
                          "mapSettings": {
                            "locInfo": "CountryRegion",
                            "locInfoColumn": "country",
                            "sizeSettings": "connections",
                            "sizeAggregation": "Sum",
                            "legendMetric": "connections",
                            "legendAggregation": "Sum",
                            "itemColorSettings": {
                              "nodeColorField": "connections",
                              "colorAggregation": "Sum",
                              "type": "heatmap",
                              "heatmapPalette": "greenRed"
                            }
                          }
                        },
                        "customWidth": "50",
                        "name": "map-inbound-by-country",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == \"inbound\"\n| where capture_source == \"vpcflow\"\n| where isnotempty(src_country)\n| summarize connections = count() by src_country\n| sort by connections desc\n| extend iso2 = src_country\n| lookup _GetWatchlist('CorelightGeoCountries') on iso2\n| project\n    [\"Country\"] = country,\n    [\"Connections\"] = connections,\n    iso2",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Inbound Connections by Source Country",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "Country",
                              "parameterName": "inbound_country_name",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "iso2",
                              "parameterName": "inbound_iso2",
                              "parameterType": 1
                            }
                          ],
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "iso2",
                                "formatter": 5
                              }
                            ],
                            "rowLimit": 10000
                          }
                        },
                        "customWidth": "50",
                        "name": "table-inbound-by-country",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": ""
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Inbound Connections by Source Country** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 27 - Copy"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == \"inbound\"\n| where capture_source == \"vpcflow\"\n| where src_country == '{inbound_iso2}'\n| extend iso2 = '{inbound_iso2}'\n| lookup _GetWatchlist('CorelightGeoCountries') on iso2\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Inbound Connection Details for Country: {inbound_country_name}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "inbound_country_name",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "table-inbound-by-country-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == \"outbound\"\n| where capture_source == \"vpcflow\"\n| where isnotempty(dest_country)\n| summarize connections = count() by dest_country\n| sort by connections desc\n| extend iso2 = dest_country\n| lookup _GetWatchlist('CorelightGeoCountries') on iso2\n| project country, connections",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Outbound Connections by Destination Country",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "map",
                          "mapSettings": {
                            "locInfo": "CountryRegion",
                            "locInfoColumn": "country",
                            "sizeSettings": "connections",
                            "sizeAggregation": "Sum",
                            "legendMetric": "connections",
                            "legendAggregation": "Sum"
                          }
                        },
                        "customWidth": "50",
                        "name": "map-outbound-by-country",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == \"outbound\"\n| where capture_source == \"vpcflow\"\n| where isnotempty(dest_country)\n| summarize connections = count() by dest_country\n| sort by connections desc\n| extend iso2 = dest_country\n| lookup _GetWatchlist('CorelightGeoCountries') on iso2\n| project\n    [\"Country\"] = country,\n    [\"Connections\"] = connections,\n    iso2",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Outbound Connections by Destination Country",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "Country",
                              "parameterName": "outbound_country_name",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "iso2",
                              "parameterName": "outbount_iso2",
                              "parameterType": 1
                            }
                          ],
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "iso2",
                                "formatter": 5
                              }
                            ],
                            "rowLimit": 10000
                          }
                        },
                        "customWidth": "50",
                        "name": "table-outbound-by-country",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": ""
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Outbound Connections by Destination Country** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 27"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == \"outbound\"\n| where capture_source == \"vpcflow\"\n| where dest_country == '{outbount_iso2}'\n| extend iso2 = '{outbount_iso2}'\n| lookup _GetWatchlist('CorelightGeoCountries') on iso2\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Outbound Connection Details for Country: {outbound_country_name}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "outbound_country_name",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "table-outbound-by-country-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "## Additional VPC Insights will appear below when Cloud Enrichment Conn Logs are present within the selected time range",
                          "style": "info"
                        },
                        "name": "text-enrichment-note"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let interval_in_hrs=datetime_diff('hour', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet interval_in_days=datetime_diff('day', {GlobalTimeRestriction:end}, {GlobalTimeRestriction:start});\nlet bin_duration=case(interval_in_hrs<=24, 1h, interval_in_days<=30, 1d, interval_in_days>=31 and interval_in_days<=90, 7d, 31d);\ncorelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where isnotempty(orig_inst_id) or isnotempty(resp_inst_id)\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where direction == \"inbound\"\n| extend security_groups = todynamic(orig_inst_sg_ids)\n| mv-expand security_group = security_groups\n| where isnotempty(security_group)\n| make-series Trend = count() default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by security_group = tostring(security_group), dest_port\n| project\n    [\"AWS Security Group\"] = security_group,\n    [\"Destination Port\"] = dest_port,\n    [\"Connections\"] = Trend\n| sort by toreal(Connections) desc",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Inbound Traffic by Security Group",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "Destination Port",
                              "parameterName": "table_inbound_by_sg_destination_port",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "AWS Security Group",
                              "parameterName": "table_inbound_by_sg_aws_security_group",
                              "parameterType": 1
                            }
                          ],
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Destination Port",
                                "formatter": 1
                              },
                              {
                                "columnMatch": "Connections",
                                "formatter": 9,
                                "formatOptions": {
                                  "palette": "blue"
                                }
                              }
                            ],
                            "rowLimit": 10000
                          }
                        },
                        "customWidth": "50",
                        "name": "table-inbound-by-sg",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where isnotempty(orig_inst_id) or isnotempty(resp_inst_id)\n| where isnotempty(orig_inst_az) and isnotempty(resp_inst_az)\n| summarize \n    total_bytes_sent = sum(bytes_out),\n    connections = dcount(session_id)\n    by orig_inst_az, resp_inst_az\n| top 20 by total_bytes_sent desc\n| project\n    [\"Originating Availability Zone\"] = orig_inst_az,\n    [\"Connections\"] = connections,\n    [\"Total Bytes Sent\"] = total_bytes_sent,\n    [\"Responding Availability Zone\"] = resp_inst_az",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Lateral Traffic between Availability Zones",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Connections",
                                "formatter": 1,
                                "numberFormat": {
                                  "unit": 17,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              },
                              {
                                "columnMatch": "Total Bytes Sent",
                                "formatter": 1,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ]
                          }
                        },
                        "customWidth": "50",
                        "name": "table-lateral-az-traffic",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Inbound Traffic by Security Group** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 26"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where capture_source == \"vpcflow\"\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where dest_port == \"{table_inbound_by_sg_destination_port}\"| where direction == \"inbound\"\n| where isnotempty(orig_inst_org_id) or isnotempty(resp_inst_org_id)\n| where  orig_inst_sg_ids contains \"{table_inbound_by_sg_aws_security_group}\"\n| sort by TimeGenerated desc",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details of Inbound Traffic for Security Group: {table_inbound_by_sg_aws_security_group} and Destination Port: {table_inbound_by_sg_destination_port}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "table_inbound_by_sg_destination_port",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 21",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where isnotempty(org_id)\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where isnotempty(orig_inst_id) or isnotempty(resp_inst_id)\n| summarize count() by org_id\n| top 10 by count_ desc",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Traffic By AWS Account",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "account_org_id",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart"
                        },
                        "customWidth": "50",
                        "showPin": false,
                        "name": "pie-traffic-by-account",
                        "styleSettings": {
                          "padding": "50px"
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where direction == \"outbound\"\n| where isnotempty(orig_inst_id) or isnotempty(resp_inst_id)\n| where isnotempty(orig_inst_name)\n| summarize total_bytes = sum(bytes_out) by orig_inst_name, src_ip, dest_ip\n| top 10 by total_bytes desc\n| project\n    [\"EC2 Instance Name\"] = orig_inst_name,\n    [\"Source IP\"] = src_ip,\n    [\"Destination IP\"] = dest_ip,\n    [\"Total Data Outbound\"] = total_bytes",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Outbound Traffic by EC2 Instance Names",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "EC2 Instance Name",
                              "parameterName": "orig_inst_name_ec2",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "Source IP",
                              "parameterName": "src_ip_ec2",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "Destination IP",
                              "parameterName": "dest_ip_ec2",
                              "parameterType": 1
                            }
                          ],
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Total Data Outbound",
                                "formatter": 1,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ]
                          }
                        },
                        "customWidth": "50",
                        "name": "table-traffic-by-ec2",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **Traffic By AWS Account** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the records in the above panel **Outbound Traffic by EC2 Instance Names** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 27"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where isnotempty(org_id)\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where isnotempty(orig_inst_id) or isnotempty(resp_inst_id)\n| where org_id == \"{account_org_id}\"",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details of Traffic for AWS Account ID: {account_org_id}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "account_org_id",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "pie-traffic-by-account-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| where direction == \"outbound\"\n| where isnotempty(orig_inst_id) or isnotempty(resp_inst_id)\n| where isnotempty(orig_inst_name)\n| where orig_inst_name == \"{orig_inst_name_ec2}\" and src_ip == \"{src_ip_ec2}\" and dest_ip == \"{dest_ip_ec2}\"",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details of Outbound Traffic for EC2 Instance Name: {orig_inst_name_ec2}, Source IP: {src_ip_ec2}, Destination IP: {dest_ip_ec2}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "orig_inst_name_ec2",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "table-traffic-by-ec2-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "selectedTab",
                    "comparison": "isEqualTo",
                    "value": "overview"
                  },
                  "name": "group-overview-tab"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 9,
                        "content": {
                          "version": "KqlParameterItem/1.0",
                          "parameters": [
                            {
                              "id": "b137c2c1-5882-47b1-82c0-e0b6e68c7482",
                              "version": "KqlParameterItem/1.0",
                              "name": "IpAddress",
                              "label": "IP Address",
                              "type": 1,
                              "timeContext": {
                                "durationMs": 86400000
                              },
                              "value": "*"
                            }
                          ],
                          "style": "pills",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces"
                        },
                        "customWidth": "50",
                        "name": "parameters - 18"
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "### If Data does not appear, then the IP Address has not been seen during the selected time range",
                          "style": "info"
                        },
                        "customWidth": "50",
                        "name": "text - 19",
                        "styleSettings": {
                          "maxWidth": "50%"
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\" and direction == \"inbound\"\r\n| summarize total_volume = sum(bytes)\r\n| project-rename [\"Total Data Inbound\"] = total_volume",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Total Data Inbound",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "Total Data Inbound",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 36,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "20",
                        "name": "tile-total-inbound"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\") \r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\" and direction == \"outbound\"\r\n| summarize total_volume = sum(bytes)\r\n| project-rename [\"Total Data Outbound\"] = total_volume",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Total Data Outbound",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "titleContent": {
                              "formatter": 1
                            },
                            "rightContent": {
                              "columnMatch": "Total Data Outbound",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 36,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "20",
                        "name": "tile-total-outbound"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\r\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\r\n| summarize Connections = count(session_id)",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Total Connections",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "Connections",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "20",
                        "name": "tile-ip-total-connections"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\r\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\r\n| summarize sourceIP = dcount(src_ip)",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Unique Source IPs",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "sourceIP",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "20",
                        "name": "tile-ip-unique-source-ips"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\r\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\r\n| summarize destinationIP = dcount(dest_ip)",
                          "size": 4,
                          "showAnalytics": true,
                          "title": "Unique Destination IPs",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "rightContent": {
                              "columnMatch": "destinationIP",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "greenRed"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal"
                                }
                              }
                            },
                            "showBorder": true
                          }
                        },
                        "customWidth": "20",
                        "name": "tile-ip-unique-dest-ips"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize Connections = dcount(uid) by capture_metadata_vpc_vpc_id\n",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "VPC IDs by Connection Count",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "Vpc_Id",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "createOtherGroup": 10,
                            "showMetrics": false,
                            "showLegend": true
                          }
                        },
                        "customWidth": "33",
                        "name": "pie-vpc-id"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| summarize Connections = dcount(uid) by direction",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Connections by Direction",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "Direction_Val",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "createOtherGroup": 10,
                            "showMetrics": false,
                            "showLegend": true
                          }
                        },
                        "customWidth": "33",
                        "name": "pie-direction"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "union withsource=TableName Corelight_*\n| where TableName !has \"conn\"\n| where (\"*\" == \"{Sensor}\" or system_name == \"{Sensor}\") \n| where (\"{IpAddress}\" == \"*\" or id_orig_h == \"{IpAddress}\" or id_resp_h == \"{IpAddress}\")\n| summarize Total = count() by TableName\n| top 20 by Total",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Corelight Data Sets",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "Table_Name",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "createOtherGroup": 10,
                            "showMetrics": false,
                            "showLegend": true
                          }
                        },
                        "customWidth": "34",
                        "name": "pie-corelight-datasets"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **VPC IDs by Connection Count** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "33",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **Connections by Direction** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "33",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **Corelight Data Sets** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "33",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 19"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (capture_metadata_vpc_vpc_id == '{Vpc_Id}')\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| sort by TimeGenerated desc",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details for VPC ID: {Vpc_Id}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Vpc_Id",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "pie-vpc-id-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where direction == '{Direction_Val}'\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\"",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details for Direction: {Direction_Val}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Direction_Val",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "pie-direction-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "let dummy_table = datatable(\n    system_name: string,id_orig_h: string, id_resp_h: string, uid: string, fuid: string, community_id: string, resp_fuids: dynamic, uids: dynamic, Type: string, TenantId: string, SourceSystem: string, MG: string, ManagementGroupName: string, Computer: string, RawData: string, _ResourceId: string\n)[];\nunion isfuzzy=true\n    dummy_table,\n    table('{Table_Name}')\n| where (\"{Sensor}\" == \"*\" or system_name == \"{Sensor}\") \n| where (\"{IpAddress}\" == \"*\" or id_orig_h == \"{IpAddress}\" or id_resp_h == \"{IpAddress}\")\n| project-away \n    TenantId, \n    SourceSystem, \n    MG, \n    ManagementGroupName, \n    Computer, \n    RawData, \n    _ResourceId",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details for Log Data Type: {Table_Name}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Table_Name",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "query - 13",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\" and direction == \"inbound\" \n| summarize Inbound_Ports = count() by transport_port = strcat(transport, \"/\", tostring(toint(dest_port)))\n| top 10 by Inbound_Ports desc",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Top Inbound Ports & Protocols",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "Porst_and_Protocol_2",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart",
                          "chartSettings": {
                            "createOtherGroup": 10,
                            "showMetrics": false,
                            "showLegend": true
                          }
                        },
                        "customWidth": "50",
                        "name": "pie-inbound-ports"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\" and direction == \"outbound\"\r\n| summarize Outbound_Ports = count() by transport_port = strcat(transport, \"/\", tostring(toint(dest_port)))\r\n| top 10 by Outbound_Ports desc",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Top Outbound Ports & Protocols",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportFieldName": "series",
                          "exportParameterName": "Porst_and_Protocol_1",
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "piechart"
                        },
                        "customWidth": "50",
                        "showPin": false,
                        "name": "pie-outbound-ports"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **Top Inbound Ports & Protocols** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            },
                            {
                              "type": 1,
                              "content": {
                                "json": "#### Click on the sections in the above panel **Top Outbound Ports & Protocols** to view more information.",
                                "style": "info"
                              },
                              "customWidth": "50",
                              "name": "text - 1"
                            }
                          ]
                        },
                        "name": "group - 20"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\" and direction == \"inbound\" \n| extend transport_port = strcat(transport, \"/\", tostring(toint(dest_port)))\n| where transport_port == '{Porst_and_Protocol_2}'",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details for Inbound Port/Protocol: {Porst_and_Protocol_2}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Porst_and_Protocol_2",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "pie-inbound-ports-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value}))\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\n| where capture_source == \"vpcflow\" and transport != \"icmp\" and direction == \"outbound\" \n| extend transport_port = strcat(transport, \"/\", tostring(toint(dest_port)))\n| where transport_port == '{Porst_and_Protocol_1}'",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details for Outbound Port/Protocol: {Porst_and_Protocol_1}",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Porst_and_Protocol_1",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "pie-outbound-ports-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\r\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \r\n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \r\n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\r\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \r\n| where (\"{IpAddress}\" == \"*\" or src_ip == \"{IpAddress}\" or dest_ip == \"{IpAddress}\")\r\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\r\n| extend transport_port = strcat(transport, \"/\", tostring(toint(dest_port)))\r\n| summarize \r\n    [\"First Seen\"] = min(TimeGenerated),\r\n    [\"Last Seen\"] = max(TimeGenerated),\r\n    [\"Total Duration\"] = sum(duration) / 1000,\r\n    [\"Bytes Sent\"] = sum(bytes_out),\r\n    [\"Bytes Received\"] = sum(bytes_in),\r\n    Total_Connections = count(),\r\n    direction_set = make_set(direction),\r\n    vpc_id_set = make_set(capture_metadata_vpc_vpc_id)\r\n    by src_ip, dest_ip, transport_port\r\n| extend \r\n    [\"Direction\"] = strcat_array(direction_set, \",\"),\r\n    [\"AWS VPC ID\"] = strcat_array(vpc_id_set, \",\")\r\n| order by Total_Connections desc\r\n| project \r\n    [\"First Seen\"], \r\n    [\"Last Seen\"], \r\n    [\"AWS VPC ID\"], \r\n    [\"Source IP\"] = src_ip, \r\n    [\"Bytes Sent\"], \r\n    [\"Direction\"], \r\n    [\"Destination IP\"] = dest_ip, \r\n    [\"Destination Port\"] = transport_port, \r\n    [\"Bytes Received\"], \r\n    [\"Total Duration\"], \r\n    [\"Total Connections\"] = Total_Connections",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connections (Top Connections/Services by Bytes Transferred)",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "exportedParameters": [
                            {
                              "fieldName": "Destination IP",
                              "parameterName": "Destination_ip",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "Source IP",
                              "parameterName": "Source_ip",
                              "parameterType": 1
                            },
                            {
                              "fieldName": "Destination Port",
                              "parameterName": "Destination_port",
                              "parameterType": 1
                            }
                          ],
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "table",
                          "gridSettings": {
                            "formatters": [
                              {
                                "columnMatch": "Bytes Sent",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              },
                              {
                                "columnMatch": "Bytes Received",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 36,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              },
                              {
                                "columnMatch": "Total Duration",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 24,
                                  "options": {
                                    "style": "decimal",
                                    "maximumFractionDigits": 2
                                  }
                                }
                              },
                              {
                                "columnMatch": "Total Connections",
                                "formatter": 0,
                                "numberFormat": {
                                  "unit": 17,
                                  "options": {
                                    "style": "decimal"
                                  }
                                }
                              }
                            ],
                            "rowLimit": 10000,
                            "filter": true,
                            "sortBy": [
                              {
                                "itemKey": "Direction",
                                "sortOrder": 1
                              }
                            ]
                          },
                          "sortBy": [
                            {
                              "itemKey": "Direction",
                              "sortOrder": 1
                            }
                          ]
                        },
                        "customWidth": "100",
                        "name": "table-connections",
                        "styleSettings": {
                          "showBorder": true
                        }
                      },
                      {
                        "type": 1,
                        "content": {
                          "json": "#### Click on the records in the above panel **Connections (Top Connections/Services by Bytes Transferred)** to view more information.",
                          "style": "info"
                        },
                        "name": "text - 21"
                      },
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_conn\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))  \n| where (\"*\" in ({VpcId:value}) or capture_metadata_vpc_vpc_id in ({VpcId:value})) \n| where (\"*\" == \"{OrgId}\" or org_id == \"{OrgId}\")\n| where (\"*\" in ({Direction:value}) or direction in ({Direction:value})) \n| where src_ip == \"{Source_ip}\" and dest_ip == \"{Destination_ip}\"\n| where capture_source == \"vpcflow\" and transport != \"icmp\"\n| extend transport_port = strcat(transport, \"/\", tostring(toint(dest_port)))\n| where transport_port == '{Destination_port}'\n",
                          "size": 0,
                          "showAnalytics": true,
                          "title": "Connection Details",
                          "noDataMessage": "No Data Found",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "showExportToExcel": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "gridSettings": {
                            "rowLimit": 10000,
                            "filter": true
                          }
                        },
                        "conditionalVisibility": {
                          "parameterName": "Destination_ip",
                          "comparison": "isNotEqualTo"
                        },
                        "name": "table-connections-drilldown",
                        "styleSettings": {
                          "showBorder": true
                        }
                      }
                    ]
                  },
                  "conditionalVisibility": {
                    "parameterName": "selectedTab",
                    "comparison": "isEqualTo",
                    "value": "ip-interrogation"
                  },
                  "name": "group-ip-interrogation-tab"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "aws_vpc_flow"
            },
            "name": "group - 7"
          },
          {
            "type": 12,
            "content": {
              "version": "NotebookGroup/1.0",
              "groupType": "editable",
              "items": [
                {
                  "type": 9,
                  "content": {
                    "version": "KqlParameterItem/1.0",
                    "parameters": [
                      {
                        "id": "9b0ed14b-2e04-4e2d-8d1a-7f6f6e9b6d03",
                        "version": "KqlParameterItem/1.0",
                        "name": "OSName",
                        "label": "Operating System",
                        "type": 2,
                        "isRequired": true,
                        "multiSelect": true,
                        "quote": "'",
                        "delimiter": ",",
                        "query": "corelight_asset_classification\n| where isnotempty(os_name)\n| distinct os_name\n| sort by os_name",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "defaultValue": "value::all",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces",
                        "value": [
                          "value::all"
                        ]
                      },
                      {
                        "id": "9b0ed14b-2e04-4e2d-8d1a-7f6f6e9b6d04",
                        "version": "KqlParameterItem/1.0",
                        "name": "TypeGroup",
                        "label": "Device Type Group",
                        "type": 2,
                        "isRequired": true,
                        "multiSelect": true,
                        "quote": "'",
                        "delimiter": ",",
                        "query": "corelight_asset_classification\n| where isnotempty(type_group)\n| distinct type_group\n| sort by type_group",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "defaultValue": "value::all",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "9b0ed14b-2e04-4e2d-8d1a-7f6f6e9b6d05",
                        "version": "KqlParameterItem/1.0",
                        "name": "TypeName",
                        "label": "Device Type Name",
                        "type": 2,
                        "isRequired": true,
                        "multiSelect": true,
                        "quote": "'",
                        "delimiter": ",",
                        "query": "corelight_asset_classification\n| where isnotempty(type_name)\n| distinct type_name\n| sort by type_name",
                        "typeSettings": {
                          "additionalResourceOptions": [
                            "value::all"
                          ],
                          "selectAllValue": "*",
                          "showDefault": false
                        },
                        "timeContextFromParameter": "GlobalTimeRestriction",
                        "defaultValue": "value::all",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      },
                      {
                        "id": "9b0ed14b-2e04-4e2d-8d1a-7f6f6e9b6d06",
                        "version": "KqlParameterItem/1.0",
                        "name": "IPAddress",
                        "label": "IP Address",
                        "type": 1,
                        "isRequired": true,
                        "query": "print '*'",
                        "queryType": 0,
                        "resourceType": "microsoft.operationalinsights/workspaces"
                      }
                    ],
                    "style": "pills",
                    "queryType": 0,
                    "resourceType": "microsoft.operationalinsights/workspaces"
                  },
                  "name": "parameters - filters"
                },
                {
                  "type": 12,
                  "content": {
                    "version": "NotebookGroup/1.0",
                    "groupType": "editable",
                    "items": [
                      {
                        "type": 3,
                        "content": {
                          "version": "KqlItem/1.0",
                          "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| where isnotempty(os_name)\n| summarize [\"Unique Devices\"] = dcount(mac) by os_name\n| top 10 by [\"Unique Devices\"]",
                          "size": 3,
                          "showAnalytics": true,
                          "title": "Total Operating Systems",
                          "noDataMessage": "No data found.",
                          "timeContextFromParameter": "GlobalTimeRestriction",
                          "showRefreshButton": true,
                          "queryType": 0,
                          "resourceType": "microsoft.operationalinsights/workspaces",
                          "visualization": "tiles",
                          "tileSettings": {
                            "titleContent": {
                              "columnMatch": "os_name",
                              "formatter": 1
                            },
                            "leftContent": {
                              "columnMatch": "Unique Devices",
                              "formatter": 12,
                              "formatOptions": {
                                "palette": "auto"
                              },
                              "numberFormat": {
                                "unit": 17,
                                "options": {
                                  "style": "decimal",
                                  "useGrouping": false,
                                  "maximumFractionDigits": 2,
                                  "maximumSignificantDigits": 3
                                }
                              }
                            },
                            "showBorder": false,
                            "size": "auto"
                          }
                        },
                        "name": "total_operating_systems"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| extend brand = coalesce(brand, \"unknown\")\n| summarize [\"Unique Devices\"] = dcount(mac) by brand\n| top 10 by [\"Unique Devices\"] desc",
                                "size": 3,
                                "showAnalytics": true,
                                "title": "Brand Breakdown",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "piechart"
                              },
                              "customWidth": "33",
                              "name": "brand_breakdown"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| extend type_name = coalesce(type_name, \"unknown\")\n| summarize [\"Unique Devices\"] = dcount(mac) by type_name\n| top 10 by [\"Unique Devices\"] desc",
                                "size": 3,
                                "showAnalytics": true,
                                "title": "Device Type Breakdown",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "piechart"
                              },
                              "customWidth": "33",
                              "name": "device_type_breakdown"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| extend type_group = coalesce(type_group, \"unknown\")\n| summarize [\"Unique Devices\"] = dcount(ip) by type_group\n| top 10 by [\"Unique Devices\"]\n desc",
                                "size": 3,
                                "showAnalytics": true,
                                "title": "Device Groupings",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "piechart"
                              },
                              "customWidth": "33",
                              "name": "device_groupings"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| where isnotempty(os_name)\n| extend os_full = iff(isnotempty(os_ver), strcat(os_name, \" \", os_ver), os_name)\n| summarize [\"Unique Devices\"] = dcount(mac) by os_full\n| top 10 by [\"Unique Devices\"] desc",
                                "size": 3,
                                "showAnalytics": true,
                                "title": "Operating System Versions",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "piechart"
                              },
                              "customWidth": "50",
                              "name": "os_versions"
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| extend sources_arr = parse_json(sources)\n| extend sources_arr = iff(set_has_element(sources_arr, \"http\") and set_has_element(sources_arr, \"dhcp\"), array_concat(sources_arr, dynamic([\"both\"])), sources_arr)\n| mv-expand source = sources_arr to typeof(string)\n| where isnotempty(source)\n| summarize Devices = dcount(ip) by source\n| top 10 by Devices desc\n",
                                "size": 3,
                                "showAnalytics": true,
                                "title": "Discovery Source",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "piechart"
                              },
                              "customWidth": "50",
                              "name": "discovery_source"
                            }
                          ]
                        },
                        "name": "group_distribution"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let assets = corelight_asset_classification\n    | where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n    | where ('*' in ({OSName}) or os_name in ({OSName}))\n    | where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n    | where ('*' in ({TypeName}) or type_name in ({TypeName}))\n    | where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n    | where isnotempty(os_name)\n    | summarize os_name = any(os_name) by ip;\ncorelight_conn\n| join kind=inner (assets) on $left.src_ip == $right.ip\n| mv-expand app to typeof(string)\n| where isnotempty(app)\n| summarize Connections = count() by os_name, app\n| top 50 by Connections desc",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Top Applications by Operating System",
                                "noDataMessage": "No data found. Requires the corelight_conn parser.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "barchart",
                                "chartSettings": {
                                  "xAxis": "os_name",
                                  "yAxis": [
                                    "Connections"
                                  ],
                                  "group": "app",
                                  "createOtherGroup": 10
                                }
                              },
                              "customWidth": "33",
                              "name": "top_apps_by_os",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs = datetime_diff('hour', now(), ago(7d));\nlet interval_in_days = datetime_diff('day', now(), ago(7d));\nlet bin_duration = case(\n    interval_in_hrs <= 24, 1h,\n    interval_in_days <= 30, 1d,\n    interval_in_days >= 31 and interval_in_days <= 90, 7d,\n    31d\n);\nlet start_time = {GlobalTimeRestriction:start};\nlet end_time = {GlobalTimeRestriction:end};\ncorelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| extend type_name = coalesce(type_name, \"unknown\")\n| make-series Trend = dcount(mac) default = 0 on TimeGenerated from start_time to end_time step bin_duration by type_name\n",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Device Types over Time",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "timechart",
                                "chartSettings": {
                                  "group": "type_name",
                                  "createOtherGroup": 10
                                }
                              },
                              "customWidth": "34",
                              "name": "device_types_over_time",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs = datetime_diff('hour', now(), ago(7d));\nlet interval_in_days = datetime_diff('day', now(), ago(7d));\nlet bin_duration = case(\n    interval_in_hrs <= 24, 1h,\n    interval_in_days <= 30, 1d,\n    interval_in_days >= 31 and interval_in_days <= 90, 7d,\n    31d\n);\nlet start_time = ago(14d);\nlet end_time = now();\nlet assets = \n    corelight_asset_classification\n    | where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n    | where ('*' in ({OSName}) or os_name in ({OSName}))\n    | where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n    | where ('*' in ({TypeName}) or type_name in ({TypeName}))\n    | where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n    | where isnotempty(device_type)\n    | summarize device_type = any(device_type) by ip;\ncorelight_conn\n| join kind=inner (assets) on $left.src_ip == $right.ip\n| extend total_bytes = coalesce(toreal(orig_bytes), real(0)) + coalesce(toreal(resp_bytes), real(0))\n| make-series Bytes = sum(total_bytes) default = 0 \n    on TimeGenerated \n    from start_time \n    to end_time \n    step bin_duration \n    by device_type",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Data Transferred by Device Type",
                                "noDataMessage": "No data found. Requires the corelight_conn parser.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "timechart",
                                "chartSettings": {
                                  "yAxis": [
                                    "Bytes"
                                  ],
                                  "group": "device_type",
                                  "createOtherGroup": 10,
                                  "ySettings": {
                                    "numberFormatSettings": {
                                      "unit": 2,
                                      "options": {
                                        "style": "decimal",
                                        "useGrouping": true
                                      }
                                    }
                                  }
                                }
                              },
                              "customWidth": "33",
                              "name": "data_transferred_by_device_type",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "let interval_in_hrs = datetime_diff('hour', now(), ago(7d));\nlet interval_in_days = datetime_diff('day', now(), ago(7d));\nlet bin_duration = case(\n    interval_in_hrs <= 24, 1h,\n    interval_in_days <= 30, 1d,\n    interval_in_days >= 31 and interval_in_days <= 90, 7d,\n    31d\n);\nlet start_time = {GlobalTimeRestriction:start};\nlet end_time = {GlobalTimeRestriction:end};\ncorelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| where isnotempty(model)\n| make-series Trend = dcount(ip) default = 0 on TimeGenerated from {GlobalTimeRestriction:start} to {GlobalTimeRestriction:end} step bin_duration by model",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Top Models over Time",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "visualization": "barchart",
                                "chartSettings": {
                                  "yAxis": [
                                    "Trend"
                                  ],
                                  "group": "model",
                                  "createOtherGroup": 20,
                                  "ySettings": {
                                    "numberFormatSettings": {
                                      "unit": 17,
                                      "options": {
                                        "style": "decimal",
                                        "useGrouping": true
                                      }
                                    }
                                  }
                                }
                              },
                              "name": "top_models_over_time",
                              "styleSettings": {
                                "showBorder": true
                              }
                            }
                          ]
                        },
                        "name": "group_trends"
                      },
                      {
                        "type": 12,
                        "content": {
                          "version": "NotebookGroup/1.0",
                          "groupType": "editable",
                          "items": [
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where TimeGenerated {GlobalTimeRestriction}\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| summarize os_name    = make_set(os_name),\n            type_name  = make_set(type_name),\n            type_group = make_set(type_group)\n  by ip\n| extend os_name    = strcat_array(os_name,    \", \"),\n         type_name  = strcat_array(type_name,  \", \"),\n         type_group = strcat_array(type_group, \", \")\n| extend os_name = coalesce(os_name, \"unknown\"), type_name = coalesce(type_name, \"unknown\"), type_group = coalesce(type_group, \"unknown\")\n| sort by ip asc\n| take 100\n| project-rename IP = ip, [\"OS Name\"] = os_name, [\"Type Name\"] = type_name, [\"Type Group\"] = type_group",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Classification Details per Host",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "IP",
                                "exportParameterName": "selected_ip",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true
                                }
                              },
                              "customWidth": "50",
                              "name": "classification_details_per_host",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| where type_group in (\"Audio & Video\", \"Smart Home\") or device_type == \"GAME_CONSOLE\"\n| summarize Count = dcount(ip) by device_type, brand, model\n| extend device_type = coalesce(device_type, \"unknown\"), brand = coalesce(brand, \"unknown\"), model = coalesce(model, \"unknown\")\n| sort by Count desc\n| take 100\n| project-rename [\"Device Type\"] = device_type, Brand = brand, Model = model",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Detected IoT (Audio, Video, Gaming)",
                                "noDataMessage": "No IoT devices detected.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true,
                                  "labelSettings": [
                                    {
                                      "columnId": "Count",
                                      "label": "Count"
                                    }
                                  ]
                                }
                              },
                              "customWidth": "50",
                              "name": "detected_iot",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ip == '{selected_ip}'",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Details for Source IP : {selected_ip}",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "selected_ip",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "device_inventory_with_classifications_drilldown - Copy",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ('*' == '{IPAddress}' or ip == '{IPAddress}')\n| extend confidence = case(\n    confidence >= 80, \"High\",\n    confidence>=20 and confidence<=39, \"Medium\",\n    confidence>=1 and confidence<=19, \"Low\",\n    \"unknown\"\n)\n| summarize mac = make_set(mac), \n        os_name = make_set(os_name), \n        os_ver = make_set(os_ver), \n        type_name = make_set(type_name), \n        type_group = make_set(type_group), \n        brand = make_set(brand), \n        model = make_set(model), \n        sources = make_set(sources) by\n        ts, ip, confidence\n| extend \n    mac = coalesce(strcat_array(mac, \", \"), \"unknown\"), \n    os_name = coalesce(strcat_array(os_name, \", \"), \"unknown\"), \n    os_ver = coalesce(strcat_array(os_ver, \", \"), \"unknown\"), \n    type_name = coalesce(strcat_array(type_name, \", \"), \"unknown\"), \n    type_group = coalesce(strcat_array(type_group, \", \"), \"unknown\"), \n    brand = coalesce(strcat_array(brand, \", \"), \"unknown\"), \n    model = coalesce(strcat_array(model, \", \"), \"unknown\"), \n    sources = coalesce(strcat_array(sources, \", \"), \"unknown\")\n| project\n    Timestamp = ts,\n    [\"IP Address\"] = ip,\n    [\"Mac Address\"] = mac,\n    [\"OS Name\"] = os_name,\n    [\"OS Version\"] = os_ver,\n    [\"Type Name\"] = type_name,\n    [\"Type Group\"] = type_group,\n    Brand = brand,\n    Model = model,\n    Confidence = confidence,\n    Sources = sources\n| sort by Timestamp desc",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Device Inventory with Classifications",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "exportFieldName": "IP Address",
                                "exportParameterName": "ip_addr",
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true
                                }
                              },
                              "name": "device_inventory_with_classifications",
                              "styleSettings": {
                                "showBorder": true
                              }
                            },
                            {
                              "type": 3,
                              "content": {
                                "version": "KqlItem/1.0",
                                "query": "corelight_asset_classification\n| where ('*' in ({Sensor}) or sensor_name in ({Sensor}))\n| where ('*' in ({OSName}) or os_name in ({OSName}))\n| where ('*' in ({TypeGroup}) or type_group in ({TypeGroup}))\n| where ('*' in ({TypeName}) or type_name in ({TypeName}))\n| where ip == '{ip_addr}'\n| sort by ts desc",
                                "size": 0,
                                "showAnalytics": true,
                                "title": "Details for Source IP : {ip_addr}",
                                "noDataMessage": "No data found.",
                                "timeContextFromParameter": "GlobalTimeRestriction",
                                "showRefreshButton": true,
                                "showExportToExcel": true,
                                "queryType": 0,
                                "resourceType": "microsoft.operationalinsights/workspaces",
                                "gridSettings": {
                                  "rowLimit": 1000,
                                  "filter": true
                                }
                              },
                              "conditionalVisibility": {
                                "parameterName": "ip_addr",
                                "comparison": "isNotEqualTo"
                              },
                              "name": "device_inventory_with_classifications_drilldown",
                              "styleSettings": {
                                "showBorder": true
                              }
                            }
                          ]
                        },
                        "name": "group_detail_tables"
                      }
                    ]
                  },
                  "name": "group_asset_classification"
                }
              ]
            },
            "conditionalVisibility": {
              "parameterName": "Tab",
              "comparison": "isEqualTo",
              "value": "asset_classification"
            },
            "name": "group - 8"
          }
        ]
      },
      "name": "Data Explorer"
    },
    {
      "type": 1,
      "content": {
        "json": "📝 **Refresh the web page to fetch details of recently collected events**"
      },
      "name": "text - 5"
    }
  ],
  "fromTemplateId": "sentinel-Corelight_Data_Explorer",
  "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
}