Skip to content

Commit

Permalink
[Security Solution] Refactor Network Top Countries to use Search Stra…
Browse files Browse the repository at this point in the history
…tegy
  • Loading branch information
patrykkopycinski committed Aug 29, 2020
1 parent 898c5c5 commit 9e52ca6
Show file tree
Hide file tree
Showing 24 changed files with 803 additions and 346 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,12 @@ import {
NetworkTlsRequestOptions,
NetworkHttpStrategyResponse,
NetworkHttpRequestOptions,
NetworkTopCountriesStrategyResponse,
NetworkTopCountriesRequestOptions,
} from './network';

export * from './hosts';
export * from './network';
export type Maybe<T> = T | null;

export type FactoryQueryTypes = HostsQueries | NetworkQueries;
Expand Down Expand Up @@ -112,6 +115,8 @@ export type StrategyResponseType<T extends FactoryQueryTypes> = T extends HostsQ
? NetworkTlsStrategyResponse
: T extends NetworkQueries.http
? NetworkHttpStrategyResponse
: T extends NetworkQueries.topCountries
? NetworkTopCountriesStrategyResponse
: never;

export type StrategyRequestType<T extends FactoryQueryTypes> = T extends HostsQueries.hosts
Expand All @@ -122,6 +127,8 @@ export type StrategyRequestType<T extends FactoryQueryTypes> = T extends HostsQu
? NetworkTlsRequestOptions
: T extends NetworkQueries.http
? NetworkHttpRequestOptions
: T extends NetworkQueries.topCountries
? NetworkTopCountriesRequestOptions
: never;

export interface GenericBuckets {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
*/

import { IEsSearchResponse } from '../../../../../../../src/plugins/data/common';
import { GeoEcs } from '../../../ecs/geo';

import {
CursorType,
Expand All @@ -18,6 +19,23 @@ import {
export enum NetworkQueries {
http = 'http',
tls = 'tls',
topCountries = 'topCountries',
}

export enum NetworkTopTablesFields {
bytes_in = 'bytes_in',
bytes_out = 'bytes_out',
flows = 'flows',
destination_ips = 'destination_ips',
source_ips = 'source_ips',
}

export enum NetworkDnsFields {
dnsName = 'dnsName',
queryCount = 'queryCount',
uniqueDomains = 'uniqueDomains',
dnsBytesIn = 'dnsBytesIn',
dnsBytesOut = 'dnsBytesOut',
}

export interface TlsBuckets {
Expand Down Expand Up @@ -58,6 +76,13 @@ export interface TlsNode {
issuers?: Maybe<string[]>;
}

export enum FlowTarget {
client = 'client',
destination = 'destination',
server = 'server',
source = 'source',
}

export enum FlowTargetSourceDest {
destination = 'destination',
source = 'source',
Expand Down Expand Up @@ -121,6 +146,94 @@ export interface NetworkHttpStrategyResponse extends IEsSearchResponse {
inspect?: Maybe<Inspect>;
}

export interface GeoItem {
geo?: Maybe<GeoEcs>;

flowTarget?: Maybe<FlowTargetSourceDest>;
}

export interface TopCountriesItemSource {
country?: Maybe<string>;

destination_ips?: Maybe<number>;

flows?: Maybe<number>;

location?: Maybe<GeoItem>;

source_ips?: Maybe<number>;
}

export interface NetworkTopCountriesRequestOptions extends RequestOptionsPaginated {
networkTopCountriesSort: NetworkTopTablesSortField;
flowTarget: FlowTargetSourceDest;
ip?: string;
}

export interface NetworkTopCountriesStrategyResponse extends IEsSearchResponse {
edges: NetworkTopCountriesEdges[];

totalCount: number;

pageInfo: PageInfoPaginated;

inspect?: Maybe<Inspect>;
}

export interface NetworkTopCountriesEdges {
node: NetworkTopCountriesItem;

cursor: CursorType;
}

export interface NetworkTopCountriesItem {
_id?: Maybe<string>;

source?: Maybe<TopCountriesItemSource>;

destination?: Maybe<TopCountriesItemDestination>;

network?: Maybe<TopNetworkTablesEcsField>;
}

export interface TopCountriesItemDestination {
country?: Maybe<string>;

destination_ips?: Maybe<number>;

flows?: Maybe<number>;

location?: Maybe<GeoItem>;

source_ips?: Maybe<number>;
}

export interface TopNetworkTablesEcsField {
bytes_in?: Maybe<number>;

bytes_out?: Maybe<number>;
}

export interface NetworkTopTablesSortField {
field: NetworkTopTablesFields;

direction: Direction;
}

export interface NetworkTopCountriesBuckets {
country: string;
key: string;
bytes_in: {
value: number;
};
bytes_out: {
value: number;
};
flows: number;
destination_ips: number;
source_ips: number;
}

export interface NetworkHttpData {
edges: NetworkHttpEdges[];

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,10 @@
* you may not use this file except in compliance with the Elastic License.
*/

import { FlowTarget, FlowTargetSourceDest } from '../../../graphql/types';
import {
FlowTarget,
FlowTargetSourceDest,
} from '../../../../common/search_strategy/security_solution/network';

import { appendSearch } from './helpers';

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,10 @@ import {
getCreateCaseUrl,
useFormatUrl,
} from '../link_to';
import { FlowTarget, FlowTargetSourceDest } from '../../../graphql/types';
import {
FlowTarget,
FlowTargetSourceDest,
} from '../../../../common/search_strategy/security_solution/network';
import { useUiSetting$, useKibana } from '../../lib/kibana';
import { isUrlInvalid } from '../../utils/validators';
import { ExternalLinkIcon } from '../external_link_icon';
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,13 +10,14 @@ import { useCallback, useEffect, useRef, useState } from 'react';
import { useSelector } from 'react-redux';

import { DEFAULT_INDEX_KEY } from '../../../../common/constants';
import { HostsEdges, PageInfoPaginated } from '../../../graphql/types';
import { inputsModel, State } from '../../../common/store';
import { createFilter } from '../../../common/containers/helpers';
import { useKibana } from '../../../common/lib/kibana';
import { hostsModel, hostsSelectors } from '../../store';
import { generateTablePaginationOptions } from '../../../common/components/paginated_table/helpers';
import {
HostsEdges,
PageInfoPaginated,
DocValueFields,
HostsQueries,
HostsRequestOptions,
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ import {
FlowTargetSourceDest,
NetworkTopCountriesEdges,
TopNetworkTablesEcsField,
} from '../../../graphql/types';
} from '../../../../common/search_strategy/security_solution/network';
import { networkModel } from '../../store';
import {
DragEffects,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ import { MockedProvider } from 'react-apollo/test-utils';
import { Provider as ReduxStoreProvider } from 'react-redux';

import '../../../common/mock/match_media';
import { FlowTargetSourceDest } from '../../../graphql/types';
import { FlowTargetSourceDest } from '../../../../common/search_strategy/security_solution/network';
import {
apolloClientObservable,
mockGlobalState,
Expand Down Expand Up @@ -76,7 +76,7 @@ describe('NetworkTopCountries Table Component', () => {
</ReduxStoreProvider>
);

expect(wrapper.find('Connect(NetworkTopCountriesTableComponent)')).toMatchSnapshot();
expect(wrapper.find('Memo(NetworkTopCountriesTableComponent)')).toMatchSnapshot();
});
test('it renders the IP Details NetworkTopCountries table', () => {
const wrapper = shallow(
Expand All @@ -101,7 +101,7 @@ describe('NetworkTopCountries Table Component', () => {
</ReduxStoreProvider>
);

expect(wrapper.find('Connect(NetworkTopCountriesTableComponent)')).toMatchSnapshot();
expect(wrapper.find('Memo(NetworkTopCountriesTableComponent)')).toMatchSnapshot();
});
});

Expand Down
Loading

0 comments on commit 9e52ca6

Please sign in to comment.