From 6b60d76031aecece9d94d24cdc5d59262be12700 Mon Sep 17 00:00:00 2001 From: Scott Brumley Date: Thu, 24 Sep 2026 17:42:08 -0400 Subject: [PATCH] fix(soc-framework-nist-ir): match the ingestion widget header to its title The 23 Sep rename off the 'lag' framing updated the viewOptions header and left the phrase's view clause carrying the old text, so the two disagreed: viewOptions header : "Ingestion Time by Source (Avg Minutes)" phrase header : "Alert Ingestion Lag by Source (Avg Minutes)" The tile caption still read 'Alert Ingestion Lag', which is the framing the rename existed to remove, and a header mismatch is a candidate cause for a widget refusing to render. Affects the Value Metrics pair. Value Driver's ingestion widgets carry no header in their phrase and were never mismatched. Verified by comparing both header values programmatically across every widget in the pack rather than by eye - reading them by eye is how this was missed. --- .../XSIAMDashboards/NIST_IR_Value_Metrics.json | 2 +- .../XSIAMDashboards/NIST_IR_Value_Metrics_Shadow.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics.json b/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics.json index 21c0818e..344e8216 100644 --- a/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics.json +++ b/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics.json @@ -1850,7 +1850,7 @@ "creation_time": 1773887140953, "description": "Time from alert anchor timestamp to arrival in XSIAM, by source (ingestion lag).", "data": { - "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Alert Ingestion Lag by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", + "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Ingestion Time by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", "time_frame": { "relativeTime": 86400000 }, diff --git a/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics_Shadow.json b/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics_Shadow.json index f5d391e2..f29e1fe6 100644 --- a/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics_Shadow.json +++ b/Packs/soc-framework-nist-ir/XSIAMDashboards/NIST_IR_Value_Metrics_Shadow.json @@ -1850,7 +1850,7 @@ "creation_time": 1773887140953, "description": "Time from alert anchor timestamp to arrival in XSIAM, by source (ingestion lag).", "data": { - "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Alert Ingestion Lag by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", + "phrase": "dataset = alerts\n| alter arrival_ms = to_integer(alert_arrival_timestamp)\n| alter anchor_ms = to_epoch(_time, \"millis\")\n| alter lag_ms = subtract(arrival_ms, anchor_ms)\n| filter lag_ms > 0 and lag_ms < 86400000\n| alter lag_minutes = divide(lag_ms, 60000)\n| comp avg(lag_minutes) as avg_lag_raw, max(lag_minutes) as max_lag_raw, count() as alert_count by alert_source\n| alter avg_lag_min = round(avg_lag_raw)\n| alter max_lag_min = round(max_lag_raw)\n| sort desc avg_lag_min\n| view graph type = column subtype = grouped layout = horizontal header = \"Ingestion Time by Source (Avg Minutes)\" xaxis = alert_source yaxis = avg_lag_min,max_lag_min xaxistitle = \"Alert Source\" yaxistitle = \"Minutes\" seriestitle(\"avg_lag_min\",\"Avg Lag (min)\") seriestitle(\"max_lag_min\",\"Max Lag (min)\") ", "time_frame": { "relativeTime": 86400000 },